setupcasino.exe

Playtech Software Installer

PLAYTECH LIMITED

This is a setup and installation application. This is the uninstaller utility registered in the Windows Control Panel for the program 12Win. The file has been seen being downloaded from gobet88.com and multiple other hosts.
Publisher:
Playtech  (signed by PLAYTECH LIMITED)

Product:
Playtech Software Installer

Description:
12Win

Version:
13.2.11.0

MD5:
a511a14283f8591c098db94c75183420

SHA-1:
54cc3ae2c120d4ed8cc59a74b8fd645b6c3db184

SHA-256:
b581a32e0734091f30d68cbd578b57dd016d75f181187d38dcc7041b42eee851

Scanner detections:
1 / 68

Status:
Inconclusive  (probably just a false positive detection)

Analysis date:
11/24/2024 11:54:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Installer.PLAYTECH
15.4.24.7

File size:
287.7 KB (294,560 bytes)

Product version:
13.2.11.0

Copyright:
Copyright (C) 2001-2009 Playtech

Original file name:
CasinoDownloader2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\setupcasino.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/23/2012 8:00:00 AM

Valid to:
3/13/2015 7:59:59 AM

Subject:
CN=PLAYTECH LIMITED, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PLAYTECH LIMITED, L=Douglas, S=Isle of Man, C=IM

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
08E8E108CB58477BBE7872C837D9D556

File PE Metadata
Compilation timestamp:
1/17/2014 6:14:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:JCv889gvgQ33+UiKRXuJ1QDLLukTyD3X8fpYnNkmcef4aaaaX1hF:0v/gg6zhXiQDfHyOpYNkmcsoDF

Entry address:
0x3533C

Entry point:
B8, 54, A4, 54, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 1D, 53, 9B, C3, 5E, 77, 18, 99, 6F, 7C, 77, A1, 65, F4, AF, FF, 6C, 10, 43, 4E, A0, 7F, 17, 37, 63, 76, 03, 95, ED, 40, BA, 09, 1C, 05, C9, 1D, CB, 56, 33, F7, 40, 63, 7E, F8, B4, 54, 4C, 12, 51, FB, A8, 78, 2A, 08, 2D, 3C, AC, 43, 89, DB, 9E, 8E, 30, 2B, 04, 00, 2F, 16, 3C, 23, C0, 33, EE, 1B, 5D, D4, 56, 8A, AB, 55, 8B, FF, 13, 3C, CD, 6F, C5, 97, 49, 32, 07, 0B, 74...
 
[+]

Entropy:
7.8310

Packer / compiler:
PECompact v2

Code size:
338 KB (346,112 bytes)

Program Uninstaller
Program name:
12Win

Uninstall string:
"C:\Casino\12Win\_SetupCasino.exe" /uninstall


The file setupcasino.exe has been seen being distributed by the following 6 URLs.

Scan setupcasino.exe - Powered by Reason Core Security