Dragons World Hack.exe

Dragons World Hack

This is a setup program which is used to install the application. The file has been seen being downloaded from doc-00-cc-docs.googleusercontent.com and multiple other hosts.
Product:
Dragons World Hack

Version:
1.0.0.0

MD5:
9c8335bbd902f5f0284d92f465d2b0c6

SHA-1:
92d592335401086ce5b60ef92249f5357b839120

SHA-256:
08d72fb5cf50340a8f31ebf165f1e4a65918bb488fb78cf6f7d8aaa70dc8c57b

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/26/2024 1:58:24 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.MSIL.GameHack
4.0.3.14710

Comodo Security
UnclassifiedMalware
21243

ESET NOD32
MSIL/GameHack.AE (variant)
8.9789

File size:
622 KB (636,928 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
Dragons World Hack.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\dragons world hack.exe

File PE Metadata
Compilation timestamp:
2/7/2014 10:05:23 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:NRc/FvO0YheDR+MvKGL3jj2kw1RQ9tbchGpVKISa8Rc/FvO0Yhe:NRcuh0kuprnkRQDIGpVZ8Rcuh

Entry address:
0x7BFEE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D3, A1, F4, 52, 00, 00, 00, 00, 02, 00, 00, 00, 80, 00, 00, 00, 1C, C0, 07, 00, 1C, A4, 07, 00, 52, 53, 44, 53, CB, 75, D2, 6F, 61, 50, CF, 4E, B3, 66, BE, D0, D2, C8, CA, 7E, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 4A, 6F, 73, 69, 70, 5C, 41, 70, 70, 44, 61, 74, 61, 5C, 4C, 6F, 63, 61, 6C, 5C, 54, 65, 6D, 70, 6F, 72, 61, 72, 79, 20, 50, 72, 6F, 6A, 65, 63, 74, 73, 5C, 44, 72, 61, 67, 6F, 6E, 73, 20, 57, 6F...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
488 KB (499,712 bytes)

The file Dragons World Hack.exe has been seen being distributed by the following 3 URLs.

Scan Dragons World Hack.exe - Powered by Reason Core Security