launcher_csgo.exe

Tolyak26

The executable launcher_csgo.exe, “Counter-Strike: Global Offensive Launcher ” has been detected as malware by 16 anti-virus scanners. This is a setup program which is used to install the application. It runs as a scheduled task under the Windows Task Scheduler. The file has been seen being downloaded from mega.nz and multiple other hosts.
Publisher:
Tolyak26

Description:
Counter-Strike: Global Offensive Launcher

Version:
1.0.0.0

MD5:
40edf2f664eeae60c5c07eb9c2e9e897

SHA-1:
0be3a93637b34bd5383e409ae46e164570a59362

SHA-256:
645f957e9f4c306f42e2db9caef46d9988f861d93ce795ab0033eadda102ef48

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
1/13/2025 1:39:24 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Agent.12204
943

Baidu Antivirus
Trojan.Win32.GameHack
4.0.3.1477

Bitdefender
Trojan.Agent.12204
1.0.20.940

Emsisoft Anti-Malware
Trojan.Agent.12204
8.14.07.07.11

ESET NOD32
Win32/GameHack (variant)
8.10021

Fortinet FortiGate
Riskware/GameHack
7/7/2014

F-Secure
Trojan.Agent.12204
11.2014-07-07_2

G Data
Trojan.Agent.12204
14.7.24

IKARUS anti.virus
Trojan-Downloader.Win32.Genome
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.180.12553

McAfee
RDN/Generic Downloader.x!kk
5600.7077

MicroWorld eScan
Trojan.Agent.12204
15.0.0.564

Norman
Agent.BCKJI
11.20140707

nProtect
Trojan.Agent.12204
14.06.30.01

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R0CBH06FS14
7.2.188

File size:
68.5 KB (70,144 bytes)

Copyright:
Tolyak26

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
768:5wCy6qlkmQAWXHBcWL08y6bWZJbxzRLDM96W1WNHDBbBI/MO12UlWBuOi:5A6qlkmQA+hc+HbqJbxFLDXd4PkGW

Entry address:
0x439C

Entry point:
55, 8B, EC, 83, C4, E0, 33, C0, 89, 45, E8, 89, 45, E4, 89, 45, E0, 89, 45, EC, B8, 74, 43, 40, 00, E8, 86, F9, FF, FF, 33, C0, 55, 68, 5A, 44, 40, 00, 64, FF, 30, 64, 89, 20, 8D, 45, EC, E8, 74, FE, FF, FF, 8B, 45, EC, E8, E8, E1, FF, FF, B8, 70, 44, 40, 00, E8, 6A, FA, FF, FF, 84, C0, 74, 4B, 6A, 01, 6A, FF, 6A, 00, 8D, 45, E0, E8, D4, FE, FF, FF, 8B, 4D, E0, 8D, 45, E4, BA, 88, 44, 40, 00, E8, F0, F3, FF, FF, 8B, 45, E4, E8, F8, F4, FF, FF, 8B, D0, 8D, 45, E8, E8, 4A, F3, FF, FF, 8B, 55, E8, 33, C9, B8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
13.5 KB (13,824 bytes)

Scheduled Task
Task name:
{679FCAF1-5954-4391-8EE6-12C9FCBDC1B4}

Trigger:
Registration (Runs on registration)


The file launcher_csgo.exe has been seen being distributed by the following 2 URLs.

https://mega.nz/temporary/.../npgxwTBJ

Remove launcher_csgo.exe - Powered by Reason Core Security