cttqw_setup_30_18a2a20.exe

Chiến Thần Tam Quốc

Dragon Top Entertainment Company Limited

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from 360play.apps.zing.vn and multiple other hosts.
Publisher:
VNG Coporation   (signed by Dragon Top Entertainment Company Limited)

Product:
Chiến Thần Tam Quốc

Description:
Chiến Thần Tam Quốc Setup

Version:
1.0.2

MD5:
bc3b8aedd2556cb3265b04ee356502e5

SHA-1:
25a6a4a5a1ee950e97e05bca3b59d015cfe3cde8

SHA-256:
57f9398f8e0f1e3f7952bcdf0fb5263f073def0b8dee03836e105bd99434d742

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 10:25:53 PM UTC  (today)

File size:
1.8 MB (1,844,288 bytes)

Product version:
1.0.2

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\cttqw_setup_30_18a2a20.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
6/8/2015 1:00:00 AM

Valid to:
6/12/2018 1:00:00 PM

Subject:
CN=Dragon Top Entertainment Company Limited, O=Dragon Top Entertainment Company Limited, L=Ha Noi, S=Ha Noi, C=VN

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0BEFFAE02435509DBCC1D8B85CBE2132

File PE Metadata
Compilation timestamp:
2/18/2010 1:52:05 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:bh9vfG77AiKLPMK2ErwHB+tSyi43zk8Ttkf6Y/mR3j:bX87AiKLPz2ErIB+64jk86fd/mpj

Entry address:
0x163C4

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, F0, 54, 41, 00, E8, 70, 04, FF, FF, 33, C0, 55, 68, 91, 6A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 4D, 6A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 42, EF, FF, FF, E8, 4D, EA, FF, FF, 8D, 55, EC, 33, C0, E8, FB, 87, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, A6, EA, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Entropy:
7.9328

Developed / compiled with:
Microsoft Visual C++

Code size:
85 KB (87,040 bytes)

The file cttqw_setup_30_18a2a20.exe has been seen being distributed by the following 50 URLs.

http://360play.apps.zing.vn/tracking/.../cttqw_setup.exe&ts=1459214368601&_v=5&_ver=4&sign_user=277662182&username=fb.kid.overnight&drive=new&zmd_cid=36&session_id=1F0189885EEED5898EB913D1&signed_request=ZPHvM1_zYlKoIXgXsBh31Ayn7DZIgxQXZXdrTe5tHdU=.eyJhbGdvcml0aG0iOiJITUFDLVNIQTI1NiIsImV4cGlyZXMiOjcyMDAsImlzc3VlZF9hdCI6MTQ1OTIxNDM1OCwiYWNjZXNzX3Rva2VuIjoiMGQwZjNmNGFhZTc4NGU2ZTk3N2I3N2M4YTQyZmU3ZmIuTnpabE1UWTVPV0k9S3pVLW1hT3EyNzFIdUNFNjgzME1TcHh3V2hPMzJvWDRBdk1yWXFYZjROdlhnRFlFSWM0VkJXaGx4LXZqQTdMZkw4RmVwWnJHNGMxSXRrMkU4YUtPTGJaOGF6S19BZEtuMHpOSHExcWtRU3QtcmlHQmxJcXlwTXV5bW1qdG4xdDhUM3QySmF0NTY4cUFDUW1QQXVLTGFHYnJzS2JCbG1oUzE3LVhHTGFjOXVxUU1ibm04cmU9IiwidWlkIjoyNzc2NjIxODJ9&code=DoHtjWJGUan24ckg9vONFKn94zOAucHGKGmslJVJH5O4OIVjKhHMBMHeTkzrpc0yRY86-GsXS3XiAWNtIx5BHYbkETD5uKv6TMrkq4RY7aLyF3lJHk0LH1Gu2jiw_3jlRaLUupZDVZvIGJ-u2AfIUZ9a5jGmstLtRpqJWs_V8ND1NULv0BkoY5Pm3Bxso4n9yL9Uf_JAMN3v1axQySaCNhyB1OViirSamXq-sTIbJNaceMSCBZx6EXa=&_src=me_homeleft_hot

http://360play.apps.zing.vn/tracking/.../cttqw_setup.exe&ts=1459161856933&_v=5&_ver=4&sign_user=256253301&username=ancumeo1979&session_id=1F018988A6AB0E1A74C51595&signed_request=R2xYfgJRx7oICtX71reFk_jUih1z0K6jcuCXGmAMyGc=.eyJhbGdvcml0aG0iOiJITUFDLVNIQTI1NiIsImV4cGlyZXMiOjcyMDAsImlzc3VlZF9hdCI6MTQ1OTE2MTg1NCwiYWNjZXNzX3Rva2VuIjoiMGQwZjNmNGFhZTc4NGU2ZTk3N2I3N2M4YTQyZmU3ZmIuTldVNU5tSTBOekU9eVcwQmJxVmw0TFZtRHRSSjhVV0JOOWVrRi1pN3FwYmhacTQ4cmFvbjA1NzdWTTdHSlJlMjBRcXVOaERneXNYVHlySFNacFI2NTVWdTFISTRVamJrUlNTbjdTdWxydFB4ZXpmeUNLV2dWZVJvQllWYzhUYWNLdnkyOUFUbnJKOVptNThzWjJKSUM0RktNcTdQQl9peUV3U0lBT0N0ZXFxUDllVTFqWVhUZ3BmeiIsInVpZCI6MjU2MjUzMzAxfQ==&code=JfP5ttQWRqGke5d3GEO2DI2FKhjgad9DSevsm1EJ9JSlus7jSlGrJKlfC-nPZW9UIQ13-Y7X4LrEeqF_OlegBmldVzjigYylL-Ges6-fVonUjNtRRwjqBJQnJDCJjre6JCmOwn667rTmo7cm8U4p4n3jKDmPa1GUJRHLYqQKG1fZF75nAHW1uNJhQABzaGyqySawk_-J6WtvdIh6-f1F8x-GOPldwXHPmePQnT_y3WGcggKhJqosBn4=&_src=megift

http://360play.apps.zing.vn/tracking/.../cttqw_setup.exe&ts=1458887061356&utm_source=Google&utm_medium=71700000014222111_Mass-150316&utm_term=CTTQ&utm_content=M00_CTTQ-hp_58700001177105333-43700010413559595&utm_campaign=240316_AT&gclid=Cj0KEQjwoM63BRDK_bf4_MeV3ZEBEiQAuQWqkctQ7kF6Z9EsVIyPTEcW9TZp2ni9QIlZ3yL5Huh9rcYaAq8D8P8HAQ&gclsrc=aw.ds&_svid=1

http://360play.apps.zing.vn/tracking/.../cttqw_setup.exe&ts=1459573460939&utm_source=Banner&utm_medium=Ad_CMW_Banner_470x246_GNAD&utm_term=CTTQ&utm_content=M15_CTTQ-572_470x246-05&utm_campaign=280316_CB&sid=none&err=1&_svid=1

http://360play.apps.zing.vn/tracking/.../cttqw_setup.exe&ts=1459087791748&utm_source=Banner&utm_medium=F_Hdol_PP_P_BRDST&utm_term=CTTQ&utm_content=M04_CTTQ-hp_900x450&utm_campaign=240316_AT&_svid=1

http://360play.apps.zing.vn/tracking/.../cttqw_setup.exe&ts=1460246487945&utm_source=Banner&utm_medium=F_Hdol_PP_P_GNLT&utm_term=CTTQ&utm_content=M15_CTTQ-572_900x450&utm_campaign=280316_CB&sid=none&err=1&_svid=1

http://360play.apps.zing.vn/tracking/.../cttqw_setup.exe&ts=1458999170544&_src=360-detailg&utm_source=360Game&utm_medium=detailg&_svid=1

http://360play.apps.zing.vn/tracking/.../cttqw_setup.exe&ts=1458999276585&utm_source=Google&utm_medium=71700000014222114_Mass-150316&utm_term=CTTQ&utm_content=M00_CTTQ-hp_58700001163497613-43700010343932831&utm_campaign=240316_AT&gclid=Cj0KEQjw5ti3BRD89aDFnb3SxPcBEiQAssnp0tekML4fUEV-afhd4v4UpZYyIY6-UdxZLRbbDHQrS00aAutD8P8HAQ&gclsrc=aw.ds&_svid=1

http://360play.apps.zing.vn/tracking/.../cttqw_setup.exe&ts=1459496419352&utm_source=Banner&utm_medium=S_Tyy_AP_FL_GNLT&utm_term=CTTQ&utm_content=M15_CTTQ-572_120x600&utm_campaign=280316_CB&sid=none&err=1&_svid=1

http://360play.apps.zing.vn/tracking/.../cttqw_setup.exe&ts=1460181869700&utm_source=Banner&utm_medium=F_Pnhanh_PP_P_GNLT&utm_term=CTTQ&utm_content=M15_CTTQ-572_1280x720&utm_campaign=280316_CB&sid=none&err=1&_svid=1

Latest 30 of 51 download URLs

Scan cttqw_setup_30_18a2a20.exe - Powered by Reason Core Security