xxswagxx cheat hack 100.exe

Internet Signup

OOO

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application xxswagxx cheat hack 100.exe by OOO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from rufile.net.
Publisher:
Microsoft Corporation  (signed by OOO )

Product:
Microsoft® Windows® Operating System

Description:
Internet Signup

Version:
6.00.2600.0000 (xpclient.010817-1148)

MD5:
7712b9c336d48828ca748038bbd8aeab

SHA-1:
a2b9304702320af800f64ef46d61c5e793b95cb4

SHA-256:
45a0b488be1f8c4f64654487b90750064b0ba6c40a60e13a44c92b0b1fa0526a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/6/2024 2:05:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.7.8.7

File size:
607 KB (621,576 bytes)

Product version:
6.00.2600.0000

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
ISIGNUP.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\xxswagxx cheat hack 100.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/22/2016 4:00:00 AM

Valid to:
6/23/2017 3:59:59 AM

Subject:
CN="OOO ""BAYKAL FORT AYTI""", O="OOO ""BAYKAL FORT AYTI""", STREET="Dzergynskogo, 25, of.511", L=Irkutsk, S=Irkutskaya, PostalCode=664011, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3893027C66B26D657A5F538754DBCC25

File PE Metadata
Compilation timestamp:
7/7/2016 7:10:06 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:9wmbIH37hh/h4d5RJKt6Nuixdoy83zAh9rxxqGc7q2Wz8XN:9wmcH373K/UtMHdJ83zC9r+G0fWzuN

Entry address:
0x1030

Entry point:
55, 8B, EC, 81, EC, E8, 03, 00, 00, 68, 74, 14, 00, 00, A1, F4, 71, 49, 00, 50, FF, 15, F8, 60, 49, 00, 85, C0, 74, 07, 33, C0, E9, 22, 02, 00, 00, 8B, 4D, E0, 2B, 4D, E8, 89, 4D, E8, 8B, 55, CC, 8B, 4D, E8, D3, E2, 89, 55, F0, FF, 15, 0C, 61, 49, 00, 8B, 45, D8, C1, E0, 75, 89, 45, D4, 8B, 55, CC, 8B, 4D, C4, D3, EA, 89, 55, C8, 8B, 45, DC, 50, FF, 15, FC, 60, 49, 00, 8B, 4D, E4, 69, C9, FF, 92, 4C, 0A, 89, 4D, E4, 8B, 55, CC, 52, FF, 15, 00, 61, 49, 00, 68, 4C, 70, 49, 00, 6A, 00, FF, 15, 04, 61, 49, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
595 KB (609,280 bytes)

The file xxswagxx cheat hack 100.exe has been seen being distributed by the following URL.

Remove xxswagxx cheat hack 100.exe - Powered by Reason Core Security