crossfire.exe

software

The executable crossfire.exe has been detected as malware by 5 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from fs12n3.sendspace.com.
Publisher:
software

Product:
software

Version:
1.0.0.0

MD5:
1848f678e02f78099643986d02bfaca7

SHA-1:
db8e869b99965a5691862c1f6e9142267b392365

SHA-256:
1ddacf4a6e0465c5fd2ed72fe38cce60426db95664f30ad15f97ce34e41b1255

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
1/13/2025 4:43:47 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.Gen2
8.3.3.4

Baidu Antivirus
Win32.Trojan.WisdomEyes.151026.9950
4.0.3.16520

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.181

McAfee
Artemis!1848F678E02F
5600.6393

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1120

File size:
2.8 MB (2,988,032 bytes)

Product version:
1.0.0.0

Copyright:
software

Trademarks:
software

Original file name:
software.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\crossfire.exe

File PE Metadata
Compilation timestamp:
5/17/2016 9:37:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:wRC83CQ4DOMzge2waAfw2am/ZA4oaBQleUJhgsVF5xL8Qcj9KtF:yC83CQ4DOMzZfw2am/ZA6Q4UJhgsD5xE

Entry address:
0x2D6A0E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.8 MB (2,968,576 bytes)

The file crossfire.exe has been seen being distributed by the following URL.

Remove crossfire.exe - Powered by Reason Core Security