counter-strike global offensive.exe

MD5:
6d22f6ae0f31136aae8432d0690add1a

SHA-1:
bf33aa5261a2f21541d3a399a57d7fb902a51a27

SHA-256:
5389a39c48914c7216fbd9e8cf29c0a043e94c9cf1e56ee93f6023113b8afbe3

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/27/2024 9:55:43 AM UTC  (today)

Scan engine
Detection
Engine version

F-Secure
Suspicious:W32/Malware.bf33aa5261!Online
5.14.151

McAfee
Artemis!6D22F6AE0F31
5600.6633

ViRobot
Worm.Win32.A.Juched.1522688[h]
2014.3.20.0

File size:
1.5 MB (1,522,688 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
9/20/2010 4:19:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ADYoP1JgW1tQ2IXUFTBVx2S8lsdu1Hy+mWdyYoltCCiTlOSp1OTC1i8nLUD7bZbE:AkUQIF2AaHTJ1Oe0O8bt

Entry address:
0xCDD08

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, 57, B8, 4C, BE, 4C, 00, E8, 65, 95, F3, FF, 33, C0, 55, 68, EA, DD, 4C, 00, 64, FF, 30, 64, 89, 20, 33, C0, 55, 68, BB, DD, 4C, 00, 64, FF, 30, 64, 89, 20, A1, 70, 50, 4D, 00, 8B, 00, E8, E1, A6, F9, FF, A1, 70, 50, 4D, 00, 8B, 00, BA, 04, DE, 4C, 00, E8, 88, A1, F9, FF, A1, 70, 50, 4D, 00, 8B, 00, BA, 04, DE, 4C, 00, E8, C7, B2, F9, FF, E8, 66, B2, FA, FF, 84, C0, 75, 43, E8, FD, AF, FA, FF, 83, 78, 08, 00, 74, 14, E8, F2, AF, FA, FF, 8B, 50, 08, A1, 70, 50, 4D, 00, 8B, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
817 KB (836,608 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to dev.ucoz.net  (193.109.246.54:80)

TCP (HTTP):
Connects to myarena.ru  (46.174.48.4:80)

TCP (HTTP):
Connects to ip-167-114-233.eu  (167.114.233.120:80)

Scan counter-strike global offensive.exe - Powered by Reason Core Security