play_videos.exe

My God

This is a setup program which is used to install the application. The file has been seen being downloaded from filmesonlinegratiis.com.
Publisher:
My God

Version:
1.0.0.0

MD5:
27c6436f0386d456900ac3ba5e55623f

SHA-1:
70fe17c225a39b72bb96ffd61383660913749018

SHA-256:
6050bae44bdda0e5c7bce41c3cb0646dcc7e0406506e589e56a185d7f0df9c30

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/15/2024 12:30:04 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.Downloader.W32.Gen
2.1.4+

Comodo Security
TrojWare.Win32.TrojanDownloader.Delf.gen
23918

K7 AntiVirus
Trojan
13.212.18331

Qihoo 360 Security
HEUR/QVM05.1.Malware.Gen
1.0.0.1077

File size:
525 KB (537,600 bytes)

Product version:
Backup

File type:
Executable application (Win32 EXE)

Language:
Uzbeque (Cirílico, Uzbequistão)

Common path:
C:\users\{user}\downloads\play_videos.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:8HwH41pOhmRoP7g+XdXVBW2W0z9OLCjm:2TShmROlTWi4LCjm

Entry address:
0x56B4C

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, B8, 6C, 69, F7, 07, E8, 6A, F0, FA, FF, 68, FC, 6B, F7, 07, E8, C0, FA, FA, FF, 8B, F0, 68, FC, 6B, F7, 07, 6A, FF, 6A, 00, E8, E8, F2, FA, FF, 8B, D8, 85, DB, 74, 0C, E8, 85, F3, FA, FF, 3D, B7, 00, 00, 00, 75, 11, 6A, 00, 6A, 00, 56, 68, FF, FF, 00, 00, E8, C7, FA, FA, FF, EB, 57, A1, BC, 80, F7, 07, 8B, 00, E8, 51, DD, FF, FF, A1, BC, 80, F7, 07, 8B, 00, C6, 40, 5B, 00, 6A, 00, A1, BC, 80, F7, 07, 8B, 00, 8B, 40, 30, 50, E8, 5C, FB, FA, FF, 8B, 0D, 48, 81, F7, 07, A1, BC...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
343 KB (351,232 bytes)

The file play_videos.exe has been seen being distributed by the following URL.

Scan play_videos.exe - Powered by Reason Core Security