gl-super_soldier_4j.exe

The executable gl-super_soldier_4j.exe has been detected as malware by 6 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from rs773p2.rapidshare.com.
MD5:
2b477979665a7da3bbbe0808c04ee2ed

SHA-1:
0691d63b4c91bd47653370d97f0d7233f416f4bd

SHA-256:
67c3d46cf5b9d203eee09a8acdbada032ba4d95548e4816669858ab9cfe5623b

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
12/25/2024 4:16:46 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.Gen
8.3.2.4

avast!
Win32:Malware-gen
2014.9-160411

Comodo Security
UnclassifiedMalware
23958

F-Prot
W32/Heuristic-KPP
v6.4.7.1.166

G Data
Win32.Trojan.Agent.88QEE9
16.4.25

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16409

File size:
481.5 KB (493,026 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\gl-super_soldier_4j.exe

File PE Metadata
Compilation timestamp:
5/25/2012 9:54:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.56

CTPH (ssdeep):
12288:SItrUsTPLxFc5yzfkbtqccRnFznU3GEfF3WQGYQpYMk/BcEin/3IWVFxmc3Yn:ztrUsTPLxFceNnU3RfDK0/z

Entry address:
0x1220

Entry point:
55, 89, E5, 83, EC, 08, C7, 04, 24, 01, 00, 00, 00, FF, 15, 5C, B2, 45, 00, E8, C8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 83, EC, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, 5C, B2, 45, 00, E8, A8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 8B, 0D, 9C, B2, 45, 00, 89, E5, 5D, FF, E1, 8D, 74, 26, 00, 55, 8B, 0D, 84, B2, 45, 00, 89, E5, 5D, FF, E1, 90, 90, 90, 90, 55, 89, E5, 5D, E9, 57, EB, 00, 00, 90, 90, 90, 90, 90, 90, 90, 55, 89, E5, 83, EC, 28, 8B, 45, 10, 89, 04, 24, E8, AF, 3C, 01...
 
[+]

Packer / compiler:
Dev-C++ 4.9.9.2

Code size:
258.5 KB (264,704 bytes)

The file gl-super_soldier_4j.exe has been seen being distributed by the following URL.

Remove gl-super_soldier_4j.exe - Powered by Reason Core Security