warmine.exe

Launcher Starter

Ivan Gritsenko

This is a setup program which is used to install the application. The file has been seen being downloaded from warmine.ru.
Publisher:
Ivan Gritsenko  (signed and verified)

Product:
Launcher Starter

Description:
Starter for K773 Launcher

Version:
0.2.3.0

MD5:
eb37ecd231f89a6939b3122412a9e6e1

SHA-1:
bb799116e0916e06b438bbb801c02915431524ad

SHA-256:
f236ff1e8bfc48d93ca72367c4a18edcca3f320ba8a8e67c299c64b8b75fbbdc

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/26/2024 6:50:25 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.161112

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
537.9 KB (550,840 bytes)

Product version:
0.2.3.0

Copyright:
Copyright (C) K773 2016

Original file name:
StreamCraft.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\warmine.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/22/2016 2:00:00 AM

Valid to:
2/20/2017 1:59:59 AM

Subject:
CN=Ivan Gritsenko, O=Ivan Gritsenko, STREET=Pyatnitskoe shosse 6-4-185, L=Moscow, S=Moscow, PostalCode=125464, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EC9D0FD39D11E038DBA574BE1ECF5691

File PE Metadata
Compilation timestamp:
11/12/2016 9:51:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:XJBizf+UVj7nPmTz+iFpVe21JkfKWYTz+iFpVe21JkfKWf:XJYfzVj7neTjde0TTjde0

Entry address:
0xAB90

Entry point:
E8, 10, 57, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 3C, 93, 41, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 4C, 91, 41, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 40, 06, 42, 00, 89, 0D, 3C, 06, 42, 00, 89, 15, 38, 06, 42, 00, 89, 1D, 34, 06, 42, 00, 89, 35, 30, 06, 42, 00, 89, 3D...
 
[+]

Code size:
93.5 KB (95,744 bytes)

The file warmine.exe has been seen being distributed by the following URL.

http://warmine.ru/.../WarMine.exe

Scan warmine.exe - Powered by Reason Core Security