proxy_sa.exe

This is a setup program which is used to install the application. It runs as a scheduled task under the Windows Task Scheduler. The file has been seen being downloaded from www3.zippyshare.com and multiple other hosts.
MD5:
25405921d1c47747fd01fd0bfe0a05ae

SHA-1:
de9ebfe4943d1d1888b8adabfef2e7d4fa4f0943

SHA-256:
cd885d84bcbdacddc27bdbd6676e376557f118f090e71e0db7c746e72c949064

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/23/2024 9:30:07 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAutoB
1.3.0.4677

Trend Micro House Call
TROJ_GEN.F47V1214
7.2.24

File size:
15.1 MB (15,806,464 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\rockstar games\gta sa\proxy_sa.exe

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.0

CTPH (ssdeep):
196608:B/DilPG7k1Cv4CJmV/UT5c2dFmefyL3nC5kjzC5TnZHCtpAdjOAZ/ss:B/ulPG7wCACJmV/UTa0ULPMZ/X

Entry address:
0x425330

Entry point:
6A, 60, 68, B8, 90, 88, 00, E8, 94, 3C, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 28, D6, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 44, 91, 85, 00, 8B, 4E, 10, 89, 0D, C8, D3, C9, 00, 8B, 46, 04, A3, D4, D3, C9, 00, 8B, 56, 08, 89, 15, D8, D3, C9, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, CC, D3, C9, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, CC, D3, C9, 00, C1, E0, 08, 03, C2, A3, D0, D3, C9, 00, 33, F6, 56, 8B, 3D, 68, 90, 85, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
4.3 MB (4,554,752 bytes)

Scheduled Task
Task name:
{2664983E-3C9C-4D11-B15D-6B25B6F20A89}

Trigger:
Registration (Runs on registration)


The file proxy_sa.exe has been discovered within the following programs.

CLEO v3.0.950  by Seemann
cleo.sannybuilder.com
About 1% of users remove it
GTA San Andreas  by Rockstar Games Inc.
Grand Theft Auto: San Andreas is an open world action-adventure video game.
www.rockstargames.com
1% remove it
 
Powered by Should I Remove It?

The file proxy_sa.exe has been seen being distributed by the following 50 URLs.

http://www3.zippyshare.com/d/69060167/.../gta_sa.exe

http://download934.mediafire.com/yi5t5n1pc8qg/.../gta_sa.exe

http://download2109.mediafire.com/1jbo09xse8pg/.../gta_sa.exe

http://download1038.mediafire.com/3hm8x139jetg/.../gta_sa.exe

http://s7933.chomikuj.pl/File.aspx?e=0IodYvIf9dn1gw0o1eWhgw3ryakWqHHEFrK8YAKGpVgDFrw8doHj719piIahRXpHAOX_znIcn7Q5Q1N7NQuOtqrdYiIxkiGNV8VVK07aC5rKX8ukYN2q5A0d_RuMAaCf&pv=2

http://download1365.mediafire.com/j0768h0bo1zg/.../gta_sa.exe

http://download2218.mediafire.com/g1gsi8d8pv2g/.../gta_sa.exe

http://download2218.mediafire.com/x2j8jxj82bqg/.../gta_sa.exe

http://download2218.mediafire.com/70rtj3z6dehg/.../gta_sa.exe

http://dc476.4shared.com/download/.../gta_sa.exe

http://download723.mediafire.com/up1hzxb2z4wg/.../gta_sa.exe

http://download726.mediafire.com/1xbljxlbk9pg/.../gta_sa.exe

http://download1611.mediafire.com/y1688akaoayg/.../gta_sa.exe

http://download2109.mediafire.com/thvlenh7mmlg/.../gta_sa.exe

http://download871.mediafire.com/9fy448pif5ig/.../gta_sa.exe

http://download726.mediafire.com/t3679jzmzmtg/.../gta_sa.exe

http://download2093.mediafire.com/fd5pgaa1h9vg/.../gta_sa.exe

http://download793.mediafire.com/vff18io7a1gg/.../gta_sa.exe

http://download793.mediafire.com/skj19x67qxqg/.../gta_sa.exe

http://download1294.mediafire.com/v934v1fuc9xg/.../gta_sa.exe

http://download1309.mediafire.com/zrhgq1kaxccg/.../gta_sa.exe

http://download1611.mediafire.com/i0on9dta8feg/.../gta_sa.exe

http://s7933.chomikuj.pl/File.aspx?e=0IodYvIf9dn1gw0o1eWhg0Ir1JcY3m520MX6dB4B7ip9nKCBHz9jrMOgKrF3wTEtFI_7VEbaSeCKq-tBTiuj9lK83j3YN_mG3-nPT2AqmfBwXD7EBSXaOV23Wbb6Bc6x&pv=2

http://download1611.mediafire.com/ni06nwsknoeg/.../gta_sa.exe

http://www3.zippyshare.com/d/69060167/.../gta_sa.exe

http://dc309.4shared.com/download/.../gta_sa.exe

http://download793.mediafire.com/aha7z7blgebg/.../gta_sa.exe

temp:gta_sa.exe

http://download723.mediafire.com/twng20d668eg/.../gta_sa.exe

http://download1611.mediafire.com/b8taej1uzmkg/.../gta_sa.exe

Latest 30 of 52 download URLs

Scan proxy_sa.exe - Powered by Reason Core Security