csgokeys_setup.exe

Internet Explorer

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable csgokeys_setup.exe, “Win32 Cabinet Self-Extractor ” has been detected as malware by 23 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from demo.ovh.eu.
Publisher:
Microsoft Corporation*  (Invalid match)

Product:
Internet Explorer

Description:
Win32 Cabinet Self-Extractor

Version:
11.00.9600.16428 (winblue_gdr.131013-1700)

MD5:
d76359886159523a8c082ff37d3b7423

SHA-1:
9e448b3ec4a7277818524b56bd797055f3d47bae

SHA-256:
106801994b18c9bddff6f6385239073080901cf67dd8bb612951e419ec94d1ef

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
11/16/2024 10:36:27 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.14769623
572

Avira AntiVirus
TR/Crypt.Xpack.79637
8.3.1.6

Arcabit
Trojan.Generic.DE15DD7
1.0.0.425

avast!
Win32:Malware-gen
2014.9-150712

AVG
Pakes2_c
2016.0.3050

Baidu Antivirus
Trojan.Win32.Dropper
4.0.3.15712

Bitdefender
Trojan.Generic.14769623
1.0.20.965

Dr.Web
Trojan.DownLoader13.53873
9.0.1.0193

Emsisoft Anti-Malware
Trojan.Generic.14769623
8.15.07.12.11

ESET NOD32
Generik.IIBVYRM (variant)
9.11854

Fortinet FortiGate
W32/Sysn.AZUX!tr
7/12/2015

F-Secure
Trojan.Generic.14768451
11.2015-12-07_1

G Data
Trojan.Generic.14769623
15.7.25

IKARUS anti.virus
Trojan.Win32.Reconyc
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.205.16384

Kaspersky
Trojan-Dropper.Win32.Sysn
14.0.0.1745

Malwarebytes
Trojan.Autoit
v2015.07.12.11

McAfee
Artemis!D76359886159
5600.6706

MicroWorld eScan
Trojan.Generic.14769623
16.0.0.579

NANO AntiVirus
Trojan.Win64.Sysn.dtfasp
0.30.24.2266

Panda Antivirus
Trj/Chgt.O
15.07.12.11

Qihoo 360 Security
Win32/Trojan.bdc
1.0.0.1015

VIPRE Antivirus
Trojan.Win32.Generic
41508

File size:
1.6 MB (1,670,656 bytes)

Product version:
11.00.9600.16428

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
WEXTRACT.EXE .MUI

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\csgokeys_setup.exe

File PE Metadata
Compilation timestamp:
10/13/2013 11:48:22 PM

OS version:
6.3

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:IKyWd8QP1tTlPcKVcpMDVJoim3r3d84UXtjNJ/D5TlTZIpi0x8HYO2VeBY4h51W:IRWd8Sv9fvm3rANNJ/DrZAi0y+4h

Entry address:
0x7F1C

Entry point:
48, 83, EC, 28, E8, 4F, 09, 00, 00, 48, 83, C4, 28, E9, 06, 00, 00, 00, CC, CC, CC, CC, CC, CC, 48, 89, 5C, 24, 08, 48, 89, 7C, 24, 10, 41, 56, 48, 81, EC, B0, 00, 00, 00, 83, 64, 24, 20, 00, 48, 8D, 4C, 24, 40, FF, 15, 89, 43, 00, 00, 90, 65, 48, 8B, 04, 25, 30, 00, 00, 00, 48, 8B, 58, 08, 33, FF, 33, C0, F0, 48, 0F, B1, 1D, F6, 1B, 00, 00, 74, 19, 48, 3B, C3, 75, 07, BF, 01, 00, 00, 00, EB, 0D, B9, E8, 03, 00, 00, FF, 15, 0D, 43, 00, 00, EB, DA, 8B, 05, DD, 1B, 00, 00, 83, F8, 01, 75, 0A, 8D, 48, 1E, E8...
 
[+]

Entropy:
7.9525  (probably packed)

Code size:
32 KB (32,768 bytes)

The file csgokeys_setup.exe has been seen being distributed by the following URL.

Remove csgokeys_setup.exe - Powered by Reason Core Security