wolfteam_latino_rush__hack_g6.exe

WindowsApplication1

The executable wolfteam_latino_rush__hack_g6.exe has been detected as malware by 12 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from s5.dosya.tc.
Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
e9bbcdb51cb2db3aab56127c2d0a89ce

SHA-1:
74172a35c11ddc1071e609a585e4785b8c05f27e

SHA-256:
b483fcaf175cc9aeca3fad6de5f1c454941fe7f977d114ba4b515deeaf43b5ce

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
12/26/2024 1:25:47 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Barys.53227
185

Arcabit
Trojan.Barys.DCFEB
1.0.0.672

Bitdefender
Gen:Variant.Barys.53227
1.0.20.1075

Emsisoft Anti-Malware
Gen:Variant.Barys.53227
8.16.08.02.01

ESET NOD32
MSIL/GameHack.FO potentially unsafe (variant)
10.13473

F-Secure
Gen:Variant.Barys.53227
11.2016-02-08_3

G Data
Gen:Variant.Barys.53227
16.8.25

McAfee
Artemis!E9BBCDB51CB2
5600.6319

MicroWorld eScan
Gen:Variant.Barys.53227
17.0.0.645

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1120

Rising Antivirus
Malware.Undefined!8.C-YoGzUgUduwI (Cloud)
23.00.65.16731

VIPRE Antivirus
Trojan.Win32.Generic
49300

File size:
1.1 MB (1,133,568 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2016

Original file name:
Wolfteam latino(Rush) Hack G6.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\users\{user}\downloads\wolfteam_latino_rush__hack_g6.exe

File PE Metadata
Compilation timestamp:
4/23/2016 2:34:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:vvpMW1B0rN6eerrUZNepMW1B0rMlrlN0pMW1B0ripMWtB0r:5MO04zr9MO0QlrLYMO0mMw0

Entry address:
0xE5ECE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
912 KB (933,888 bytes)

The file wolfteam_latino_rush__hack_g6.exe has been seen being distributed by the following URL.

Remove wolfteam_latino_rush__hack_g6.exe - Powered by Reason Core Security