red alert 2_tr12trainer.exe

The executable red alert 2_tr12trainer.exe has been detected as malware by 24 anti-virus scanners. The file has been seen being downloaded from s44.nitroflare.com.
MD5:
2fef6f12a61d151e54d8dfafd099908c

SHA-1:
5e478e74733576b1d1f569415e60429cb8082314

SHA-256:
d8a75d64027b4bbe34ef4fe7b956a43e89151ceb65b880640595e2b01c9b4905

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
11/29/2024 9:34:18 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.825457
698

AhnLab V3 Security
Win-Trojan/Xema.variant
2014.12.11

Avira AntiVirus
TR/Agent.20992.K
7.11.194.70

Baidu Antivirus
Trojan.Win32.GameHack
4.0.3.1538

Bitdefender
Trojan.Generic.825457
1.0.20.335

Bkav FE
HW32.Packed
1.3.0.6267

Comodo Security
UnclassifiedMalware
20331

Emsisoft Anti-Malware
Trojan.Generic.825457
8.15.03.08.01

ESET NOD32
Win32/GameHack.HH (variant)
9.10859

Fortinet FortiGate
W32/Generic!tr
3/8/2015

F-Secure
Trojan.Generic.825457
11.2015-08-03_1

G Data
Trojan.Generic.825457
15.3.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.8.5.0

McAfee
RDN/Generic PUP.x!b2e
5600.6832

MicroWorld eScan
Trojan.Generic.825457
16.0.0.201

Norman
Smalltroj.CTTU
11.20150308

nProtect
Trojan/W32.Agent.20992.LN
14.12.10.01

Panda Antivirus
Generic Malware
15.03.08.01

Qihoo 360 Security
Win32/Trojan.0dc
1.0.0.1015

Sophos
Generic PUA FO
4.98

Trend Micro House Call
TROJ_GEN.R0C1C0EJ614
7.2.67

Trend Micro
TROJ_GEN.R0C1C0EJ614
10.465.08

VIPRE Antivirus
Trojan.Win32.Generic
35622

ViRobot
Trojan.Win32.S.Agent.20992.QB[h]
2014.3.20.0

File size:
20.5 KB (20,992 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
5/21/2004 3:33:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
384:4zfAY5T+e+t95iEmBJs61Kh0shkBaMy9dFMg6v6RlSGj6OFexk+OFe:zY9+7t95wP1Kh0sWBah9d2g6vS5BFex4

Entry address:
0xC640

Entry point:
60, BE, 00, 90, 40, 00, 8D, BE, 00, 80, FF, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Entropy:
7.0946

Packer / compiler:
UPX 2.90LZMA

Code size:
16 KB (16,384 bytes)

The file red alert 2_tr12trainer.exe has been seen being distributed by the following URL.

Remove red alert 2_tr12trainer.exe - Powered by Reason Core Security