cs-go.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from am4-r1f4-stor02.uploaded.net and multiple other hosts.
MD5:
e2eda1086a633069d820c01da173e27c

SHA-1:
52bcd3335843884abb76039babb3d3fd54d84041

SHA-256:
8bca4798e7f171edc539054451660f620f809ce1543ab55c6bcb55b2a15698dc

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/23/2024 8:24:32 PM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM06.2.Malware.Gen
1.0.0.1015

File size:
3.7 MB (3,838,982 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\cs-go.exe

File PE Metadata
Compilation timestamp:
12/1/2013 6:08:28 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:BPvIpkCst3KvVMF0XJ7e578DfXm8lK+2PYlK:5ZLt3KvaF0sRKRJ2PF

Entry address:
0x108AF

Entry point:
E8, 9C, 58, 00, 00, E9, 78, FE, FF, FF, 55, 8B, EC, 83, EC, 04, 89, 7D, FC, 8B, 7D, 08, 8B, 4D, 0C, C1, E9, 07, 66, 0F, EF, C0, EB, 08, 8D, A4, 24, 00, 00, 00, 00, 90, 66, 0F, 7F, 07, 66, 0F, 7F, 47, 10, 66, 0F, 7F, 47, 20, 66, 0F, 7F, 47, 30, 66, 0F, 7F, 47, 40, 66, 0F, 7F, 47, 50, 66, 0F, 7F, 47, 60, 66, 0F, 7F, 47, 70, 8D, BF, 80, 00, 00, 00, 49, 75, D0, 8B, 7D, FC, 8B, E5, 5D, C3, 55, 8B, EC, 83, EC, 10, 89, 7D, FC, 8B, 45, 08, 99, 8B, F8, 33, FA, 2B, FA, 83, E7, 0F, 33, FA, 2B, FA, 85, FF, 75, 3C, 8B...
 
[+]

Code size:
98 KB (100,352 bytes)

The file cs-go.exe has been seen being distributed by the following 50 URLs.

http://am4-r1f4-stor02.uploaded.net/.../a28a8713-bc3f-480d-9035-8d48eebff1a0

http://am4-r1f4-stor02.uploaded.net/.../3ce8ae98-d90b-431c-8f61-688f7e7ad95f

http://am4-r1f4-stor02.uploaded.net/.../577269b0-ae2c-428f-8f5a-96db9f6602a4

http://am4-r1f4-stor02.uploaded.net/.../a4824d99-7ebb-49e7-97d1-9a1782453585

http://am4-r1f10-stor03.uploaded.net/.../d8a67e8f-2c22-434d-8aab-d80aaf4ed25e

http://am4-r1f4-stor02.uploaded.net/.../b4041b7b-f960-4057-9c9c-dc637d37d902

http://am4-r1f4-stor02.uploaded.net/.../7c96132f-c38b-4930-a39c-692ff0f5a4ac

http://am4-r1f4-stor02.uploaded.net/.../6475e783-fdb1-43e5-8c80-14c6d2623ee1

http://am4-r1f4-stor02.uploaded.net/.../01955c69-c338-411a-ab69-6c68a7f9bdbc

http://am4-r1f4-stor02.uploaded.net/.../5d7e37d2-e732-4642-ab53-8dc188b532d5

http://am4-r1f4-stor02.uploaded.net/.../9a475218-3d82-46d1-9bd1-f3b33141117a

http://am4-r1f4-stor02.uploaded.net/.../2ba9ac05-69e8-4095-b764-5ee6ef87757e

http://am4-r1f4-stor02.uploaded.net/.../d321b4dc-bac8-4c4d-8795-9e2896717e50

http://am4-r1f4-stor02.uploaded.net/.../c5c015c9-34e0-4d2d-be82-cd4007cb6854

http://am4-r1f4-stor02.uploaded.net/.../67e25c24-ae33-4ede-bd7e-70fbed2789e0

http://am4-r1f4-stor02.uploaded.net/.../1082e13a-25fe-4a79-a4d9-fece49ea2d92

http://am4-r1f4-stor02.uploaded.net/.../a5dc2187-2bff-4c1c-9a50-ae17e28f3bc8

http://am4-r1f4-stor02.uploaded.net/.../99962a85-c319-41e2-a6fe-e5846f437926

http://am4-r1f4-stor02.uploaded.net/.../6b4869e0-4229-4059-a731-7af0d6a6e9f0

http://am4-r1f4-stor02.uploaded.net/.../4a124d74-4173-4121-91a5-52099762307f

http://am4-r1f4-stor02.uploaded.net/.../abc0ca55-9e64-45f7-8c2d-09cc63164266

http://am4-r1f4-stor02.uploaded.net/.../55168bdd-abc6-405d-85a7-79ceb82369fa

http://am4-r1f4-stor02.uploaded.net/.../90007a40-5948-4557-91aa-91e2565d8d47

http://am4-r1f4-stor02.uploaded.net/.../06824b54-be75-44db-9cae-879741e22e9b

http://am4-r1f4-stor02.uploaded.net/.../27dd0af6-9762-40cb-811a-009a886bd237

http://am4-r1f4-stor02.uploaded.net/.../f4b7f5b8-7f45-441e-ad3b-4313d1e51e7e

http://am4-r1f4-stor02.uploaded.net/.../a4b4980d-3d75-4e32-90cb-05bc5bce3070

http://am4-r1f4-stor02.uploaded.net/.../e4ec7c12-6ed5-4e41-8281-d857c29cff6d

http://am4-r1f4-stor02.uploaded.net/.../037acf6b-5b9d-4a48-8726-c4e1ceea7fa3

http://am4-r1f4-stor02.uploaded.net/.../2756865f-fa99-43a3-b6bc-72aa942f187d

Latest 30 of 99 download URLs

Scan cs-go.exe - Powered by Reason Core Security