goat_simulator.exe

WindowsApplication1

Microsoft

This is a setup program which is used to install the application. The file has been seen being downloaded from cluster011.ovh.net and multiple other hosts.
Publisher:
Microsoft

Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
02542cc96b9053485109c38052e446fa

SHA-1:
3cc4be78cb5123769f157733a60653d87d05e5fb

SHA-256:
45afa308fcc571e202b9bb3196a54df19c4c822c542d923b65da0bb070af54f3

Scanner detections:
9 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/27/2024 7:49:04 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.419722
867

Bitdefender
Gen:Variant.Kazy.419722
1.0.20.1315

Emsisoft Anti-Malware
Gen:Variant.Kazy.419722
8.14.09.20.05

F-Secure
Gen:Variant.Kazy.419722
11.2014-20-09_7

G Data
Gen:Variant.Kazy.419722
14.9.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.7.8.0

McAfee
Artemis!02542CC96B90
5600.7001

MicroWorld eScan
Gen:Variant.Kazy.419722
15.0.0.789

Trend Micro House Call
TROJ_GEN.R047H09GP14
7.2.263

File size:
6.3 MB (6,646,784 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2014

Original file name:
Goat Simulator.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\goat_simulator.exe

File PE Metadata
Compilation timestamp:
7/18/2014 5:03:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
196608:hnmGFnUnvGFnunvGj5nHyNIlfMl8p2tE6Lc9B9wRQ5eOG3eDGFn:hnmYnUnvYnunvCS+S5dLc9B9wuS38Yn

Entry address:
0x65407E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9647

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
6.3 MB (6,627,840 bytes)

The file goat_simulator.exe has been seen being distributed by the following 6 URLs.

Scan goat_simulator.exe - Powered by Reason Core Security