Official Wreckfest Trainer.exe

WindowsApplication1

This is a setup program which is used to install the application. The file has been seen being downloaded from fileshare1270.dfiles.eu.
Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
6eeebbbe25aa7b601aed8eb46de99e20

SHA-1:
0091371d15963c557cd1ab8163f8225660eed214

SHA-256:
531bdc4c136285370c92379ac96310e0d8bfc7279de3e8478f49fb1323717e1b

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/29/2024 1:38:43 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Hacktool.MSIL.GameHack
4.0.3.1654

ESET NOD32
MSIL/GameHack.NL potentially unsafe application
8.0.319.0

File size:
600.5 KB (614,912 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
Official Wreckfest Trainer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\official wreckfest trainer.exe

File PE Metadata
Compilation timestamp:
8/4/2015 7:24:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:8ar9U/41V8XZYfi1vgn519BEf7iVgmIdwvOnkU8LYkXK:fr9TyXh6GfG1IyI8LR

Entry address:
0x945EE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4D, 03, C1, 55, 00, 00, 00, 00, 02, 00, 00, 00, 1C, 01, 00, 00, 1C, 60, 09, 00, 1C, 2A, 09, 00, 52, 53, 44, 53, 7B, 2B, 1B, 3B, E9, FC, 07, 45, 80, 0A, A4, 1C, 67, F6, C6, 26, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 4D, 69, 63, 68, 61, 65, 6C, 5C, 64, 6F, 63, 75, 6D, 65, 6E, 74, 73, 5C, 76, 69, 73, 75, 61, 6C, 20, 73, 74, 75, 64, 69, 6F, 20, 32, 30, 31, 33, 5C, 50, 72, 6F, 6A, 65, 63, 74, 73, 5C, 57, 69, 6E...
 
[+]

Entropy:
7.8987

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
585.5 KB (599,552 bytes)

The file Official Wreckfest Trainer.exe has been seen being distributed by the following URL.

Scan Official Wreckfest Trainer.exe - Powered by Reason Core Security