gtasa-multiplayer-mod.exe

GTA Multiplayer mod

NSIS

The executable gtasa-multiplayer-mod.exe has been detected as malware by 6 anti-virus scanners. The program is a setup application that uses the Nullsoft Scriptable Install System installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from multi-theft-auto-san-andreas.turbodisk.net.
Publisher:
NSIS

Product:
GTA Multiplayer mod

Version:
2.2

MD5:
3e16e2f6c312593344ee5b6f74c8bd6a

SHA-1:
fbe70e9f7d2117df331934c58611f23cf724ba3d

SHA-256:
737abb8074c6414c36c71cb4a39589cba4b55ff2d234cfc2f5f38c5d7640246d

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
12/28/2024 1:08:07 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160414-2

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.E.gen
4.6.5.141

McAfee
Trojan.Artemis!7097878B1F6E
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.1093.0

File size:
1.1 MB (1,117,902 bytes)

Product version:
2

Copyright:
NSIS

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:rIEdDwW6laFKUAaCR5vmC4Qk7DV9i1uHXfZGwv4xBw/rolaFKUAaCO:rIkUbL9RMC4QyDguHvowwzw4L9O

Entry address:
0x30CB

Entry point:
EB, 02, 87, CB, F3, F7, C0, 07, 08, EC, 68, 20, C7, 4F, 46, 8B, C8, 33, DB, 3B, C1, 32, CE, 01, DF, 85, C6, 33, D8, 0F, BF, D7, E8, 00, 00, 00, 00, 85, E9, 75, 08, 0F, AF, FA, B9, F2, 1E, B2, 0A, 0F, AF, CE, 29, C7, B4, 5A, 81, ED, AE, DA, 00, 00, 86, E4, 81, ED, A6, 0B, 00, 00, 5A, 47, 80, DD, 79, 69, DD, ED, AA, 78, DF, 8B, F5, 78, 04, 38, C8, FF, CE, C7, C0, 9E, 73, 79, 37, 0F, B7, C1, F7, C7, 4A, CC, 83, 95, 8D, 5D, 00, 09, ED, C6, C4, B4, BD, 82, 12, DB, B2, 69, F1, CB, 6E, 18, 30, FF, CB, BF, 00, 00...
 
[+]

Packer / compiler:
FSG v1.10 (Microsoft Visual C++ 6.0 / 7.0)

Code size:
22.5 KB (23,040 bytes)

The file gtasa-multiplayer-mod.exe has been seen being distributed by the following URL.

Remove gtasa-multiplayer-mod.exe - Powered by Reason Core Security