gta vice city.exe

SelfCert

Era Tehno

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable gta vice city.exe, “Create a self-signed digital certificate” has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from bare-crazy-lead.ru.
Publisher:
Microsoft Corporation  (signed by Era Tehno)

Product:
SelfCert

Description:
Create a self-signed digital certificate

Version:
12.0.6606.1000

MD5:
aacfdcfd37b785d691487272a3326729

SHA-1:
2f4e94e05ce5c8617a4ce7dde3a785d235e8d250

SHA-256:
999e7ce50a23d145947dc03433de71daf827e41845d15fb1e493a2cfcdcfbea1

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/6/2024 6:27:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.11.7

File size:
844 KB (864,232 bytes)

Product version:
12.0.6606.1000

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
Selfcert.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\gta vice city.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/14/2016 3:00:00 AM

Valid to:
6/15/2017 2:59:59 AM

Subject:
CN=Era Tehno, O=Era Tehno, STREET="KIROVOGRADSKAJa Street, Building 42", L=Moscow, S=Moscow, PostalCode=117534, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
69A05FDE494793353A4495A3D4440917

File PE Metadata
Compilation timestamp:
7/13/2016 10:12:39 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1290

Entry point:
55, 8B, EC, B8, 28, 8B, 00, 00, E8, B3, FF, FF, FF, 53, 56, 57, C6, 45, F4, 3E, 8B, 85, 74, 77, FF, FF, 69, C0, F2, 41, 19, 10, 89, 85, 70, 77, FF, FF, 8B, 8D, 70, 77, FF, FF, 0F, AF, 8D, 74, 77, FF, FF, 89, 8D, 70, 77, FF, FF, 68, 84, 80, 44, 00, FF, 15, 18, C0, 43, 00, 8B, 95, 74, 77, FF, FF, 03, 95, 74, 77, FF, FF, 89, 95, 70, 77, FF, FF, 6A, 00, FF, 15, 10, C0, 43, 00, 68, 90, 80, 44, 00, FF, 15, 1C, C0, 43, 00, 68, 94, 80, 44, 00, 8B, 85, 74, 77, FF, FF, 50, FF, 15, 24, C0, 43, 00, FF, 15, 0C, C0, 43...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
235.5 KB (241,152 bytes)

The file gta vice city.exe has been seen being distributed by the following URL.

http://bare-crazy-lead.ru/download56227/.../load

Remove gta vice city.exe - Powered by Reason Core Security