pou_pc_game.exe

Setup

The executable pou_pc_game.exe has been detected as malware by 23 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from cluster007.ovh.net.
Product:
Setup

Version:
0.0.8.1

MD5:
78db376928063c0b32b6354ada959964

SHA-1:
3ac783f5c7bf603b740ba9e5b95a914d4f2f767d

SHA-256:
557ec3a292c39aaad2992f421a825024055d40597285b5b81bb1a63bda62d5ec

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
11/27/2024 7:42:26 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1720814
358

Agnitum Outpost
Trojan.Surveyer
7.1.1

Avira AntiVirus
TR/Rogue.4551680
8.3.1.6

avast!
Win32:Malware-gen
2014.9-160211

AVG
MSIL4
2017.0.2836

Baidu Antivirus
Trojan.MSIL.Surveyer
4.0.3.16211

Bitdefender
Trojan.GenericKD.1720814
1.0.20.210

Comodo Security
UnclassifiedMalware
22104

Emsisoft Anti-Malware
Trojan.GenericKD.1720814
8.16.02.11.05

ESET NOD32
MSIL/Surveyer (variant)
10.11621

Fortinet FortiGate
MSIL/Surveyer.W!tr
2/11/2016

F-Secure
Trojan.GenericKD.1720814
11.2016-11-02_5

G Data
Trojan.GenericKD.1720814
16.2.25

IKARUS anti.virus
Trojan.MSIL.Surveyer
t3scan.1.8.9.0

McAfee
Artemis!78DB37692806
5600.6492

MicroWorld eScan
Trojan.GenericKD.1720814
17.0.0.126

Norman
Suspicious_Gen4.HCFJN
11.20160211

nProtect
Trojan.GenericKD.1720814
15.05.13.01

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R002C0EKG14
7.2.42

Trend Micro
TROJ_GEN.R002C0EKG14
10.465.11

VIPRE Antivirus
Trojan.Win32.Generic
40200

ViRobot
Trojan.Win32.S.Agent.4551680.A[h]
2014.3.20.0

File size:
4.3 MB (4,551,680 bytes)

Product version:
0.0.8.1

Copyright:
Copyright © 2013

Original file name:
Pou PC Game.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
4/27/2014 1:45:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:T42IB7m2321jgBCwWDPXBSFoKUdYtQvFsFbEp3Szk1k9k2k:EK28awLXBSXmCo6ib

Entry address:
0x454BFE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
4.3 MB (4,533,760 bytes)

The file pou_pc_game.exe has been seen being distributed by the following URL.

Remove pou_pc_game.exe - Powered by Reason Core Security