1421261188_ovisetup.exe

OpenIV

New Technology Studio

This is a setup and installation application. The file has been seen being downloaded from files.gtagaming.com and multiple other hosts.
Publisher:
New Technology Studio

Product:
OpenIV

Description:
OpenIV setup

Version:
2.0.0.0

MD5:
066592317474a4f8421972ce64131c4d

SHA-1:
5a224267f29dfbc9324a1f9db794898d37c74613

SHA-256:
6fdd2781218e1d717ef047142ce4fb2fdaceaa18d39376a264961f1bc181faa1

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/28/2024 7:33:02 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Genome
2015.02.01

McAfee
Artemis!066592317474
5600.6866

Trend Micro House Call
Suspicious_GEN.F47V0116
7.2.34

ViRobot
Trojan.Win32.S.Agent.5599744[h]
2014.3.20.0

File size:
5.3 MB (5,599,744 bytes)

Product version:
2.0.0.0

Copyright:
© New Technology Studio

Original file name:
ovisetup.exe

File type:
Executable application (Win32 EXE)

Language:
Rusça (Rusya)

File PE Metadata
Compilation timestamp:
1/14/2015 8:33:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:ccgMwaJVScBYXvLQjMd21nJ2SmWlSnleHzBYNTaG6UqebuOHinriHPDPL9sbxbyt:j4LnwhPebuOHtHr2emSMadxfcjFVpPW

Entry address:
0x31A400

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, 57, B8, 0C, D5, 70, 00, E8, 91, 3D, CF, FF, 33, D2, 55, 68, 3F, A4, 71, 00, 64, FF, 32, 64, 89, 22, A1, 1C, 70, 6E, 00, E8, 39, CD, FC, FF, A1, 1C, 70, 6E, 00, E8, D7, D2, FC, FF, 33, C0, 5A, 59, 59, 64, 89, 10, EB, 24, E9, 84, E2, CE, FF, 01, 00, 00, 00, 88, D7, 41, 00, 50, A4, 71, 00, 8B, C8, 33, D2, A1, 1C, 70, 6E, 00, E8, 5A, D4, FC, FF, E8, 91, E5, CE, FF, 5F, 5E, 5B, E8, 3D, EB, CE, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.1 MB (3,248,640 bytes)

The file 1421261188_ovisetup.exe has been seen being distributed by the following 2 URLs.

Scan 1421261188_ovisetup.exe - Powered by Reason Core Security