harry_potte_and_the_chamber_of_secrets[www.gamevicio.com.br].exe

Harry Potter and the Chamber of Secrets BR

GameVicio

This is a setup program which is used to install the application. The file has been seen being downloaded from dc213.4shared.com and multiple other hosts.
Publisher:
GameVicio

Product:
Harry Potter and the Chamber of Secrets BR

Version:
Versão 1.00

MD5:
de8c07a307f2202170903cdffe570afd

SHA-1:
5dd351e68ccc689c7361c32b3a79d6c51a6d9b9e

SHA-256:
4dfd4e574d3dba495301ac4ad1893ca0bd8bca3021ee852cf937f6c76075f1a7

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/24/2024 5:07:44 AM UTC  (today)

Scan engine
Detection
Engine version

F-Prot
W32/Trojan5.KR (exact, not disinfectable)
4.6.5.141

McAfee
Artemis!F1D202938E99
5600.6500

NANO AntiVirus
Trojan.Win32.Newweb.cyrsvl
0.30.26.4437

File size:
658.8 KB (674,575 bytes)

Copyright:
GameVicio ©

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\downloads\harry_potte_and_the_chamber_of_secrets[www.gamevicio.com.br].exe

File PE Metadata
Compilation timestamp:
10/4/2005 11:26:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:1ZiBvijaoAG8HOaJHo1u6B8qzX+VeFMI0fQ8K4h:1ZihgaoSOUyB8+XgeFps

Entry address:
0x32D3

Entry point:
83, EC, 20, 53, 55, 56, 33, F6, 57, 89, 74, 24, 18, BD, 68, 91, 40, 00, 89, 74, 24, 14, C6, 44, 24, 10, 20, FF, 15, 30, 70, 40, 00, 56, FF, 15, 80, 72, 40, 00, 68, 8C, 92, 40, 00, 68, 40, 3B, 42, 00, A3, F0, 43, 42, 00, E8, DC, 27, 00, 00, BB, 00, B4, 42, 00, BF, 00, 04, 00, 00, 53, 57, FF, 15, B8, 70, 40, 00, E8, 79, FF, FF, FF, 85, C0, 75, 24, 68, FB, 03, 00, 00, 53, FF, 15, B4, 70, 40, 00, 68, 84, 92, 40, 00, 53, E8, B6, 27, 00, 00, E8, 59, FF, FF, FF, 85, C0, 0F, 84, 46, 01, 00, 00, BE, 00, A0, 42, 00...
 
[+]

Code size:
22.5 KB (23,040 bytes)

The file harry_potte_and_the_chamber_of_secrets[www.gamevicio.com.br].exe has been seen being distributed by the following 4 URLs.

http://dc213.4shared.com/download/.../hp2_traduo.exe