plants-vs-zombies-en.exe

Plants vs Zombies

LuckyCityGames

The executable plants-vs-zombies-en.exe has been detected as malware by 3 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from plants-v-zombies.ar.softonic.com.
Publisher:
LuckyCityGames

Product:
Plants vs Zombies

Version:
2.0.0.0

MD5:
1aec43c2abf22318f38313e1c516d962

SHA-1:
729856a7bbb35d6c12bf49ec29626f3337bf4a2f

SHA-256:
7f92711463fde4d1b3fd3588a6f47d0df7da7ebde3541226722eff34191b621b

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
11/24/2024 7:05:55 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Gen:Variant.Strictor.98928
16.05.26

F-Secure
Variant.Strictor.98928
5.15.96

Norman
Gen:Variant.Strictor.98928
19.05.2016 05:17:13

File size:
3.4 MB (3,564,398 bytes)

Product version:
4.7.1.0

Copyright:
Copyright by LuckyCityGames, 2015/10/29

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\plants-vs-zombies-en.exe

File PE Metadata
Compilation timestamp:
1/26/2015 8:49:24 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:qcsoSLM9/q8EOA5iXT+s0j3KWm06cFFohwa17BygVYX:qXvLM9C6A8O3KW6cajpVYX

Entry address:
0xC120

Entry point:
55, 8B, EC, B9, 11, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, 14, 91, 40, 00, E8, D4, 85, FF, FF, 33, C0, 55, 68, 90, C9, 40, 00, 64, FF, 30, 64, 89, 20, 33, C0, A3, D8, 0F, 41, 00, 33, FF, 33, C0, A3, 04, 10, 41, 00, E8, FD, CD, FF, FF, 0A, 05, A0, C9, 40, 00, E8, 02, CE, FF, FF, 33, C0, A3, 00, 10, 41, 00, E8, FA, CA, FF, FF, B8, F8, 0F, 41, 00, E8, DC, 77, FF, FF, E8, AF, 98, FF, FF, 8B, F0, 6A, 0A, B9, A4, C9, 40, 00, 8B, 15, 84, 0B, 41, 00, 8B, C6, E8, A5, 98, FF, FF, 8B, C6, E8, 7A, 96...
 
[+]

Entropy:
7.9073

Developed / compiled with:
Microsoft Visual C++

Code size:
44 KB (45,056 bytes)

The file plants-vs-zombies-en.exe has been seen being distributed by the following URL.

Remove plants-vs-zombies-en.exe - Powered by Reason Core Security