greencity_setup.exe

MyPlayCity Inc

The application greencity_setup.exe by MyPlayCity Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from files2.myplaycity.com and multiple other hosts. While running, it connects to the Internet address 184.173.181.49-static.reverse.softlayer.com on port 80 using the HTTP protocol.
Publisher:
MyPlayCity Inc  (signed and verified)

Version:
9.3.0.0

MD5:
f11ef6c5f4dbca4cc3ccfb5e12d062c7

SHA-1:
410f96dcde1af5b5a82b697f8087e4211264867a

SHA-256:
71d0e83aeb3f86785e8c7ccef3b808a3e024bfa07668900b44510ae5217a2656

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 5:05:10 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.MyPlayCity.Installer.Meta (L)
16.6.5.23

File size:
2.3 MB (2,378,368 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/3/2012 9:00:00 PM

Valid to:
8/1/2015 8:59:59 PM

Subject:
CN=MyPlayCity Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=MyPlayCity Inc, L=Alexandria, S=Virginia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4849CA3C762A3ED2D31F1C8C95D39684

File PE Metadata
Compilation timestamp:
11/8/2013 12:03:19 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:J1CuISjvgZzSxksy2BX6VBxzyTyTTfRQy4l:J1atSHy2BX6VPayk

Entry address:
0x1B6034

Entry point:
55, 8B, EC, 83, C4, F0, B8, 0C, E0, 5A, 00, E8, 1C, 47, E5, FF, A1, 3C, 06, 5D, 00, 8B, 00, E8, 98, 11, F1, FF, A1, 3C, 06, 5D, 00, 8B, 00, B2, 01, E8, C6, 2E, F1, FF, 8B, 0D, D4, 07, 5D, 00, A1, 3C, 06, 5D, 00, 8B, 00, 8B, 15, A0, 5E, 5A, 00, E8, 8A, 11, F1, FF, A1, 3C, 06, 5D, 00, 8B, 00, E8, CE, 12, F1, FF, E8, 5D, FF, E4, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.7 MB (1,787,392 bytes)

The file greencity_setup.exe has been seen being distributed by the following 2 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 50.97.129.131-static.reverse.softlayer.com  (50.97.129.131:80)

TCP (HTTP):
Connects to 184.173.181.49-static.reverse.softlayer.com  (184.173.181.49:80)

Remove greencity_setup.exe - Powered by Reason Core Security