halocesetup_es_1.00.exe

Microsoft Games Setup

Microsoft Corporation

This is a setup and installation application. The file has been seen being downloaded from hce.halomaps.org and multiple other hosts.
Publisher:
Microsoft Corporation

Product:
Microsoft Games Setup

Description:
Microsoft Games AutoRun/Setup

Version:
1.1.1.18

MD5:
9c93c080f49f8dc69c4f6a96d14cfc93

SHA-1:
f088862c625d576fa6830b132f02749c9ac53559

SHA-256:
f1838d4b5ce085b21302f4827a2bca2108c16c8f442a732ff5e0b9ed59eb32d7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 6:56:01 PM UTC  (today)

File size:
170 MB (178,233,344 bytes)

Product version:
1.1.1.18

Copyright:
© 2004 Microsoft Corp.

Trademarks:
© Microsoft Corp.

Original file name:
Setup.Exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\halocesetup_es_1.00.exe

File PE Metadata
Compilation timestamp:
4/20/2004 5:30:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
3145728:BwRuFLdzWKcVGhk51d8sHf7iZH6JC57pT7rFd7Baof8zElUj:ORuFL8Kc8hk5r8sHSH6oJ1Fd7Eo0jj

Entry address:
0x5BE9B

Entry point:
6A, 60, 68, 48, 71, 47, 00, E8, 2D, 3C, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 3D, FC, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 38, F1, 46, 00, 8B, 4E, 10, 89, 0D, 90, E4, 48, 00, 8B, 46, 04, A3, 9C, E4, 48, 00, 8B, 56, 08, 89, 15, A0, E4, 48, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 94, E4, 48, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 94, E4, 48, 00, C1, E0, 08, 03, C2, A3, 98, E4, 48, 00, 33, F6, 56, 8B, 3D, 74, F1, 46, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
7.9995

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
440 KB (450,560 bytes)

The file halocesetup_es_1.00.exe has been seen being distributed by the following 34 URLs.

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=36586714483FDAF6C79E01F4DC6090C6&w={ts '2016-11-23 10:35:06'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=7C3C6DBABE6B275224D6A666EF4F78AF&w={ts '2016-04-25 17:02:25'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=822F4253EB457D892E04EB86C2114C34&w={ts '2016-04-24 17:40:53'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=7529F24F28426CE8EAB9421E70CDDE74&w={ts '2016-10-26 21:56:25'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=90C500BF4DA3E411086683168EA68A71&w={ts '2016-05-22 00:38:58'}

http://dl3.halomaps.org/dl.cfm?fid=3947&f=halocesetup_es_1.00.exe&S=3&h=6FC6EA6977AF23F8C4797171739F22CE

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=804380AD19DDE3D525923E4D8759CD3F&w={ts '2016-02-25 21:07:59'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=82062D9A348F596396EDBD9E6997BED5&w={ts '2016-11-06 00:39:39'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=8A90D3BCB74724A35BC53C59CCBF9129&w={ts '2016-01-26 22:06:48'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=9BA1CB08393A2B978F21CF2CC3F2C566&w={ts '2016-08-14 15:19:52'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=6576F47D3346825CE10BBC3CF932C307&w={ts '2016-11-21 17:02:43'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=798C7334AF56A0EE4E6E6098F58F9E97&w={ts '2015-04-09 00:48:54'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=6A2EF65ACF898C6459CC662E1E2BBE91&w={ts '2016-09-14 18:11:43'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=9BF1A736F9239C70A7F59F990340B539&w={ts '2015-12-10 21:41:18'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=1A32CE579AF04096A0F172618D9FBE35&w={ts '2016-08-01 20:01:01'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=8EC8F9C9731FCE11A0C8EBBD7B05C7F6&w={ts '2016-09-06 01:49:57'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=108E47C5258D08FF6A01D9D75F214F52&w={ts '2016-06-29 14:31:54'}

http://hce.halomaps.org/index.cfm?fid=3947&action=now&hcode=8AA41C3D73541C82BF940E0382F80FE4&w={ts '2015-06-01 00:50:49'}

Latest 30 of 34 download URLs

Scan halocesetup_es_1.00.exe - Powered by Reason Core Security