cube_world.exe

Setup

The executable cube_world.exe has been detected as malware by 12 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from gryyy.pl and multiple other hosts.
Product:
Setup

Version:
0.0.8.1

MD5:
cd1d5ab8c022bcf5ef9fbae17f192551

SHA-1:
6481d471ba721c92a0f507d9b75cf04b79d078a7

SHA-256:
cdf97293bc2fe94a9c5d6073fbd639cea11d9a48c8ee4d22dbf5b440ef02aa7c

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
11/27/2024 3:58:31 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MSIL2
2017.0.2807

Baidu Antivirus
Trojan.MSIL.Surveyer
4.0.3.16312

Comodo Security
UnclassifiedMalware
18025

ESET NOD32
MSIL/Surveyer (variant)
10.9618

Fortinet FortiGate
MSIL/Surveyer.Q!tr
3/12/2016

IKARUS anti.virus
Trojan.MSIL2
t3scan.2.2.29

K7 AntiVirus
Trojan
13.176.11613

McAfee
Artemis!CD1D5AB8C022
5600.6463

Norman
Suspicious_Gen4.FTSFP
11.20160312

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R0CBB01CD14
7.2.72

VIPRE Antivirus
Trojan.Win32.Generic
27900

File size:
3.6 MB (3,729,408 bytes)

Product version:
0.0.8.1

Copyright:
Copyright © 2013

Original file name:
cube_world.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
11/30/2013 3:36:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:+LbELbALbILbELbU8+8ZKUdYXzg4FyGXSvFs3bug:+LQL0LsLQL1+8g/PY0bu

Entry address:
0x3354AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
3.2 MB (3,356,160 bytes)

The file cube_world.exe has been seen being distributed by the following 2 URLs.

Remove cube_world.exe - Powered by Reason Core Security