Safe
Grand Theft Auto: San Andreas executable; 4213 days old, 2667 submitters, zero tier-1 malicious detections, benign telemetry contact.
aa07fcdc8723a2831f…df95034fe3The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file exhibits a clean engine profile with zero malicious detections across 68 reporting engines, including all major tier-1 vendors (Kaspersky, BitDefender, ESET-NOD32, F-Secure, Fortinet, GData, Avast, AVG, Avira, Emsisoft). Its 4213-day submission history and 3394 total submissions from 2667 unique sources confirm it as a widely-distributed, long-established commodity. The filename matches the legitimate 2004 commercial game. Unsigned status is normal for pre-2010 software. The triggered heuristic on direct-IP contact is a false positive: the contacted IPs belong to Microsoft (20.99.*, 131.253.33.203) and Windows Update infrastructure, not attacker C2. Behaviour shows ambient system discovery and installer-typical persistence, not malware indicators.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/68 malicious; tier1Malicious=0; tier1ReportedClean=15 (Avast, BitDefender, Kaspersky, ESET-NOD32, F-Secure, Fortinet, GData, Emsisoft, Avira, AVG all undetected)
prevalence.classification=common_old; 2667 unique submitters, 3394 submissions since 2014-12-14 — widely distributed legitimate software
filename 'gta-sa.exe' matches Grand Theft Auto: San Andreas (commercial game, 2004); unsigned status normal for pre-2010 software
behaviour: T1547.001 (registry persistence) + 15 ambient techniques; no malicious sandbox verdict; contacted IPs are Microsoft telemetry ranges (20.99.*, 131.253.33.203) and Windows Update, not C2
triggeredHeuristics 'MalwareTips.Synth.DirectIpC2' fired but evidence shows benign Windows/game telemetry, not malware C2 infrastructure
- Zero malicious detections across 68 engines; 15 tier-1 vendors all clean
- 4213-day submission history (since 2014) with 3394 submissions from 2667 unique sources
- Filename matches legitimate commercial game (Grand Theft Auto: San Andreas, 2004)
- No malicious sandbox verdict; no malicious dropped children; no malicious contacted hosts
- Contacted IPs are Microsoft and Windows Update ranges, not attacker infrastructure
This file is safe. It is the legitimate Grand Theft Auto: San Andreas game executable with a 12-year clean history and zero tier-1 malware detections. No action is required.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- a83f:8110:0:0:1302:0:3000:200
- 23.216.147.64
- a83f:8110:2800:0:2800:0:1800:0
- 23.216.147.76
- 20.99.132.105
- 131.253.33.203
- 20.99.184.37
- a83f:8110:0:0:64ca:1f00:0:0
- 20.99.185.48
- 192.229.211.108
- C:\Windows\System32\spp\store\2.0\cache\cache.dat
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER46C8.tmp.WERInternalMetadata.xml
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER47E1.tmp.csv
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER4821.tmp.txt
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER4DAE.tmp.WERInternalMetadata.xml
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 18 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidencea83f:8110:0:0:1302:0:3000:200 · 23.216.147.64 · a83f:8110:2800:0:2800:0:1800:0
0 detections across 74 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- gta-sa.exe
- Size
- 5.69 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- aa07fcdc8723a2831f77a35491dea6cdd58f6733e3ac69a10ddf5cdf95034fe3
- MD5
- d9cb35c898d3298ca904a63e10ee18d7
- SHA-1
- 586ef3c963a4102a70c67070b6f654b6a73e696b
- PE imphash
- ce6e06224c447c55c5c18a038022c0dc
- First seen (VT)
- 12/14/2014, 8:11:26 AM
- Last analysis (VT)
- 6/23/2026, 4:29:53 PM
- First scan (MalwareTips)
- 6/27/2026, 4:26:17 AM
- Last scan (MalwareTips)
- 6/27/2026, 4:26:17 AM
- Community reputation
- -9flagged
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.