grand-theft-auto-online.exe

Cagolig

Destiny Dream S.A.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application grand-theft-auto-online.exe, “Cagolig Setup ” by Destiny Dream S.A has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.repositoryshareflash.com and multiple other hosts.
Publisher:
Huful   (signed by Destiny Dream S.A.)

Product:
Cagolig

Description:
Cagolig Setup

Version:
3.6.3.0

MD5:
979b22f1c1d6067eafc9e464d3892d73

SHA-1:
17f330974f8147ae6742bb342c2d5c4b9d579556

SHA-256:
2d704bbb02d96367ec48e19a081e16650bee8faf2f0ac52ea2c646d0df27de6f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/26/2024 11:17:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.DestinyD.Installer (M)
16.4.10.16

File size:
989.7 KB (1,013,448 bytes)

Product version:
2.0

Copyright:
program

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\grand-theft-auto-online.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 2:55:11 PM

Valid to:
10/2/2016 4:36:18 PM

Subject:
CN=Destiny Dream S.A., O=Destiny Dream S.A., L=Clarens, S=Vaud, C=CH

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11217A75EB912AE2167326222C18D9E2357F

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Ko9v/Sb8ISdMPNf/kLkfz8HF2+7jDBVCyP39KvlDVJx:K6SkaPNXkQfziF2sjL8l/x

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9262

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file grand-theft-auto-online.exe has been seen being distributed by the following 50 URLs.

http://www.repositoryshareflash.com/c?x=Y7Z7IU2JVgZrK3gz5CWrDp1wTA88ynWnDc7r7ssmsFM=&c=SYPM5np4Vfwc3z9qwALjkCOl7ZXEeo9Gy3K/XfOTAXtfgQD6MzY3jmwzQ38DhPrIFc3UCssAapNfkcsYp bv//LkUvRRJS8cm5Y/mhvIvOtH7tVFdOlcwdPsTWAyIJjRMeurmWQr5tfyCc/ShctG UnZ9Z9gmd5rb3/LuzkXOI6u Zx6 YjDyv5gCg8XERvd&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.nowconecptcentral.com/c?x=Gj dBCiESQGMMw1I1UXQn1VMJRiv 1rDb6hrxeQml6g=&c=ceclYeXCzROihysP8HUQg8qSgnGa7l/6uPCSJOgyh5AKO W83jBYXyRSsJVJBgGMD/epCJ acVErVnb2bgHou ci2cjiX1ls52nlwsfNq FkToYuyDvYpOS2Ls1PmZtm0VrCIEM8OGZHdt93qbFWPQ==&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.bulkcyclecenter.com/c?x=e9wYNwjMJuDSGPRTsD3QFGtMxOnSOkwWeUusy ZlRfE=&c=q4JXgpioh8jZQM1OW978dr9/LHIOkenSbdug5W8zQ8mFrPiFQ0VXHCDamkTAt15yN TPAimSftRTvk/qjHnylXqYn2lSEiawKlb6s64aZikpG3QZIUCX6dkl Dvmfli4ZtdGgpfXSJsZJjqvS2YLzg==&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.cleansignsconecpt.com/WVl6OTRQV2hqYTBGWWNIaG9Vbm8zZW01dEpUSkdibGR0WlhKQ2NIQk1TMHA2Y21GelMxZHllRFZ6Tm1GeE5rcEhheVV6UkNaalBUSk5Xa1pRTkdvNFVGQnJlVmhJYlc5RVYwaGhOalowVkhwR2JHdFhVMVJFYldWMVVtbE9PVXhEU0NVeVFtZ3hPRmN4YUhWWE9XTldWMDUwY0ZSR2VFWldNVTV0Y2xOR2FVOHlZVXh5UTA5aU1WRjZabFJ0VUUxV1JucE9Ra0ZKU0ZsYU9VSjRjbE5qVTFoclVubGhSalp1VVdsd2VFeFNVU1V5UWs5SWVVWmhVSE0wUm1SV1NVa3lSa00wUm05WlJucFRjakZuUmt0WU4xRWxNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05WjNKaGJtUXRkR2hsWm5RdFlYVjBieTF2Ym14cGJtVXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROQkpUSkdKVEpHZDNkM0xuSnZZMnR6ZEdGeVoyRnRaWE11WTI5dEpUSkdWaVV5UmtkVVFVOXViR2x1WlE9PQ==

http://www.tagsendheart.com/c?x=2h1 2zLTPk4XINdEdXc5ESYy6Tzm48oi1do4Q6A4QTw=&c= hhSSDs5qmlZ OViEIw/1I 8A7qqxBQe9/ArTpg/SkBvOUDeqOaqpn70Zrkfe/f0v5WIuo6HwRSIw7TEcHAHrVLJP0ZjZTgR4ICvmbx4XIkYF7hVC219it1Ci8koU7Hc5v YDD/DWu1Py0XTpizalfXx5dfgkPcf3bf6uC2pofAaYFtPYjEOx1PXR3e47ZIz&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.sendcurrentfarm.com/c?x=rL8if7cZvye3CLnskwErd7VFhkwKl/fIYZUPnYfLDtY=&c=C4U0K22HEDlw5BHaZgC7ZHMbjnaei1sI6S3q5hikL7xJ6elO zliMHJvhv/DOpexhZRu1QvH3UQOUGkSdNqsvt/WKLfJ CljDpRRsSDgXntpNjWMlSrCK8sbB6xh3jq/4ZitmyDTyzJ0hfVEla8IXuL4Y/bydWbQ9wObN/YxIkwU3y6Deeh49jRxqUEKQO/v&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.gifttowndelivery.com/c?x=ajrse TAVcv8vrmg82oUOOTG2pc mmzPicSWg5iwBQk=&c=Sw//9qhMaAPlHxmMWDuboo0B/4iUpKoscXmWLnglewBqtbsQ6d716Yt3oKjmrnS hynMszfQ4YzZ2l1GGbemfYeSok6q2DfBXkx30EOGYAc9CYqcaolZs ullk1bfP0TaN73F5O276xWO4rngamg V14ThBOWN906bsgWF7mYDE=&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.toursheartbits.com/c?x=/6JCnOVKqQCVQrcgavbkup/7YRVQgwr7XKm/dn/EGbA=&c=18c4KOmxv9pqkapkXw27w51PH5n tuPxQfuk2atqLVvzgdcMDVNuHQdT7ixcRZiD74YCjdUu1ThyjZ7YqiUJmtbBYGI14zZt7f6PYiDUOA mM OdSn7XWAROR31XpGVnjiZRy6s3 bvk1OH1M7AuxCaoR brXIycGJDjEDyrT84=&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.toursheartbits.com/c?x=aIHF9Y6r0UkLfPV6n7RO7a5oIPgMc529aadxqXoYehM=&c=RrcmO8W0S6QNxpZrFkM3OnVPllYG2MUq7eMa BW9tCB4XBAv R0gLs0OTxNHLEn2DgYsEJmjQha9C4I5VRqIN13cPt2G/3Y U64V075W8GS3QSaWIAFPtJtMOy5Vz9WNOkw2RHbtYajSSyEIY3SGDfRm76bV1SP4/wyTmX7l77E=&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.presentfuntowers.com/c?x=gjL9wxZUr6D1PpaQRsLx9ffNGI0BLd02v DsP2mYT6U=&c=WtTCOok 5beIPFHM c0/pABrGrzjJEfABga1/FXgKmulZGZdCoBN o/dAg1LBol7q11tpJyh3OEQufi2i7KcxYXKH0vLSbzt/RaHMqP8NzL8Y9cz59 9ST8Pp6rXSrWykTvxB7rLmPAK3X03zf5tRg==&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.presentupdateguard.com/c?x=cwFCsuJynBLF0s1G3Xzx440AdA8y9ZHASZlZwq6819Y=&c=G6tbxMmSwZubePSVY2vbGTCnpHTWNDf xfGBqmiSTY/y4q7Z9Mx uZt8Jehhv7e4u0RUkUaYXe1NZhg KyWkwRDxjIlgM98Oow2m79c4DG0kPEbeRbtJM3tmuxr9B0Z1oMsbp5Ai34vUxXSwJ2p 5mAiBWGeSXFqURCVpzw4eq4=&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.cleansignsconecpt.com/c?x=xQcKnR0BHAnCfblT3HGbijj5NB/54Z RknHl kaJG4w=&c=mywlJkadHU4VHZ4Hi5fdWuqp2OqvS9ReFvYwcW460zyOhcjy0koo/vhFmeFZMCbtnw2q6mTycg1AExZy9oLqopouLbqjyRJ5xlmalvGcEE5yMf83nd21 PGJ2mQPKMNTr5DrA4V0xayMiqEWe43EMg==&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

Latest 30 of 81 download URLs

Remove grand-theft-auto-online.exe - Powered by Reason Core Security