grand_theft_auto_san_andreas.exe

Setup

The executable grand_theft_auto_san_andreas.exe has been detected as malware by 20 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from gryyy.pl and multiple other hosts.
Product:
Setup

Version:
0.0.8.1

MD5:
a298a2b0062d34b3f459cc56a873b963

SHA-1:
c2da02dcd0716b5d2befb4dd519604f0fe7eb00b

SHA-256:
9fc9f69c639f55b57a6ede9ddcdc3d9f3b4c178a5364aa013829be156831523e

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
11/27/2024 3:40:59 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1719225
818

AegisLab AV Signature
Hoax.MSIL.Agent
2.1.4+

Avira AntiVirus
TR/Rogue.5420544
7.11.177.52

AVG
MSIL4
2015.0.3296

Baidu Antivirus
Trojan.MSIL.Surveyer
4.0.3.14119

Bitdefender
Trojan.GenericKD.1719225
1.0.20.1565

Comodo Security
UnclassifiedMalware
19739

Emsisoft Anti-Malware
Trojan.GenericKD.1719225
8.14.11.09.08

ESET NOD32
MSIL/Surveyer (variant)
8.10530

Fortinet FortiGate
MSIL/Surveyer.W!tr
11/9/2014

F-Secure
Trojan.GenericKD.1719225
11.2014-09-11_1

G Data
Trojan.GenericKD.1719225
14.11.24

IKARUS anti.virus
Trojan.MSIL.Surveyer
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.183.13611

McAfee
Artemis!A298A2B0062D
5600.6952

MicroWorld eScan
Trojan.GenericKD.1719225
15.0.0.939

nProtect
Trojan.GenericKD.1719225
14.10.08.01

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R02PB01HO14
7.2.313

VIPRE Antivirus
Trojan.Win32.Generic
33742

File size:
5.2 MB (5,420,544 bytes)

Product version:
0.0.8.1

Copyright:
Copyright © 2013

Original file name:
Grand Theft Auto San Andreas.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\grand_theft_auto_san_andreas.exe

File PE Metadata
Compilation timestamp:
2/27/2014 3:58:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:T42IB7m2321jgBCwWDPXBSFoKUdYtQvFsAbEp3SWv42IB7m:EK28awLXBSXtClK

Entry address:
0x528DFE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
5.2 MB (5,402,624 bytes)

The file grand_theft_auto_san_andreas.exe has been seen being distributed by the following 3 URLs.

Remove grand_theft_auto_san_andreas.exe - Powered by Reason Core Security