fly hack trainer.exe

The application fly hack trainer.exe has been detected as a potentially unwanted program by 24 anti-malware scanners. The file has been seen being downloaded from download2214.mediafire.com and multiple other hosts.
Version:
1.8.0.0

MD5:
f6071938620435e20ab04f9b1b22144d

SHA-1:
ba0b4c180e352f09e37ce2b9e3611183fe23495c

SHA-256:
fbc1335243892b120e37d56e2be29f6dc82d91d80530f33844369f24d8ada0c5

Scanner detections:
24 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 4:24:18 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.14495187
389

Agnitum Outpost
HackTool.CheatEngine
7.1.1

Arcabit
Trojan.Generic.DDD2DD3
1.0.0.642

AVG
Skodna.GameHack
2017.0.2867

Baidu Antivirus
Hacktool.Win32.CheatEngine
4.0.3.16112

Bitdefender
Trojan.Generic.14495187
1.0.20.60

Clam AntiVirus
Trojan.Dropper-26973
0.98/21511

Comodo Security
ApplicUnwnt.Win32.HTool.A
23951

Emsisoft Anti-Malware
Trojan.Generic.14495187
8.16.01.12.09

ESET NOD32
Win32/HackTool.CheatEngine.AB potentially unsafe (variant)
10.12847

Fortinet FortiGate
Riskware/CheatEngine
1/12/2016

F-Prot
W32/Trojan2.NMHW
v6.4.7.1.166

F-Secure
Trojan:W32/Agent.DSOA
11.2016-12-01_3

G Data
Trojan.Generic.14495187
16.1.25

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.9.5.0

K7 AntiVirus
Unwanted-Program
13.212.18379

Malwarebytes
HackTool.GamesCheat.Gen
v2016.01.12.09

McAfee
RDN/Generic PUP.z!gq
5600.6523

MicroWorld eScan
Trojan.Generic.14495187
17.0.0.36

nProtect
Trojan.Generic.14495187
16.01.08.02

Panda Antivirus
Trj/CI.A
16.01.12.09

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16110

SUPERAntiSpyware
Trojan.Agent/Generic
9390

VIPRE Antivirus
Trojan.Win32.Delf.abt
46410

File size:
686.3 KB (702,738 bytes)

Product version:
1.2

File type:
Executable application (Win32 EXE)

Language:
Dutch (Netherlands)

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:HEDCJJDXb8qWvvMyesvleMkWzChpBTfgYvVtcgwSuLnKteV:HmQGbvNvjkJPKuMlXH

Entry address:
0x93BBC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 34, 39, 49, 00, E8, 18, 29, F7, FF, A1, F0, 9D, 49, 00, 8B, 00, E8, 60, 57, FC, FF, A1, F0, 9D, 49, 00, 8B, 00, C6, 40, 5B, 00, 8B, 0D, FC, 9C, 49, 00, A1, F0, 9D, 49, 00, 8B, 00, 8B, 15, CC, 36, 49, 00, E8, 55, 57, FC, FF, A1, F0, 9D, 49, 00, 8B, 00, E8, C9, 57, FC, FF, E8, 08, 06, F7, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5863

Developed / compiled with:
Microsoft Visual C++

Code size:
587.5 KB (601,600 bytes)

The file fly hack trainer.exe has been seen being distributed by the following 9 URLs.

http://download2214.mediafire.com/7fld29bgypyg/.../fly hack trainer.exe

http://download2214.mediafire.com/t1sgmu3pnjtg/.../fly hack trainer.exe

http://download2214.mediafire.com/5sekc2sa13cg/.../fly hack trainer.exe

http://download1263.mediafire.com/63qrnxlazfmg/.../fly hack trainer.exe

Remove fly hack trainer.exe - Powered by Reason Core Security