2____wa_update-3.6.31.0_beta_installer.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer.
MD5:
25a49bd36c7a938319dc234f3b305910

SHA-1:
20eac200f647c984dc7d343aaab3537c702780e2

SHA-256:
cf1d917f5f60be495adc81cfffabc6909d58f1735d8a901811dc088f95afea16

Scanner detections:
6 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/27/2024 7:45:09 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Renos
7.1.1

Bkav FE
W32.Clod548.Trojan
1.3.0.4959

McAfee
Artemis!4E9EB8E55E57
5600.6923

Norman
Suspicious_Gen2.SLRON
11.20141207

Rising Antivirus
PE:Trojan.Win32.Generic.125941BD!307839421
23.00.65.141205

Trend Micro House Call
Suspici.68433547
7.2.341

File size:
1.4 MB (1,519,023 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\pc worms armageddon fr+patch+update multijoueurs [all][win]djinsaneboxx\2____wa_update-3.6.31.0_beta_installer.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:g8mop2j8C5ANppzdRCBnXx1koUfYWIptKqcz0YGuRJuB6MJS/Y+fj5:zmoIj8a0pyXx1SJstKqczLJudo//N

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 2____wa_update-3.6.31.0_beta_installer.exe has been seen being distributed by the following 17 URLs.

about:internet

http://s7257.chomikuj.pl/File.aspx?e=5i2nJJ6BMo2hghFeAYJMhbWEYMPhTio-NcaB02fOvKjUrWPAIxQfA_-t1tcHbPczG_CWUU14xC4b8PBGiSRIWiviHAPZF4GFOFx6IoiNmBlcuPXYkXji-86m5jjAa1DAXUNqYbTxAD3vk3d5rjCAMYqIhdlw5zdoLi9bk0igLrw&pv=2

http://s7257.chomikuj.pl/File.aspx?e=5i2nJJ6BMo2hghFeAYJMhbWEYMPhTio-NcaB02fOvKh8UiuXNd7hG519b3FdtEmBDklet00nCHJ6uoldB_QaMYRzgJ_Bkjsq0_o2aMiS2fXXjWIUqMqhjcquPyL-6Nr1PK-gStwzHPILbNcfs7gWZH9JhX8X1mtLwyamIDMbBbk&pv=2

http://s7257.chomikuj.pl/File.aspx?e=5i2nJJ6BMo2hghFeAYJMhbWEYMPhTio-NcaB02fOvKjcuQXtT_PudMklyZ_QUEZP6tIhAs779cC8n85xszO92FwEIfqd9bwCTnFLQZX7PL2vvLGQw3_SqkU0pI9OyKhOnhtPnqtCe76HSIsLP4my7JOaU4rTTJjwPE3bpOgfj-I&pv=2

http://s7257.chomikuj.pl/File.aspx?e=5i2nJJ6BMo2hghFeAYJMhbWEYMPhTio-NcaB02fOvKj_cwnkOWcE7ycD_yYgbSE3Bt7icuFwgroaVKIUG3KyVFY-EBgH7fCPgGfLNnD4J_ND18LHGIMVoE9ZEoY1VQqiCPd1iWuG5xNO7v1fjFFN9J3IxcL9P18obv8rIuMBe48&pv=2

http://s7257.chomikuj.pl/File.aspx?e=5i2nJJ6BMo2hghFeAYJMhbWEYMPhTio-NcaB02fOvKikZ8tk07MgTBdusAuaU5mflHU7loNSwcIP-UuelqXdP-oQUQic8f9gKpor2zIDcgGnbnTSK0NbrD6KwHkXf2qTFmKKJjY7YFW356-TTwL5NGZV_HppYqqotbS4Heai4fw&pv=2

https://onedrive.live.com/download.aspx?cid=3E44E53F1E9ADA25&resid=3E44E53F1E9ADA25!393&ithint=.exe

http://s7257.chomikuj.pl/File.aspx?e=5i2nJJ6BMo2hghFeAYJMhbWEYMPhTio-NcaB02fOvKh6e4MkFm0nCe1JMTUc-aLtT3BiXWdat7tBLd8-Mqli6czps98VkG-Hmgwq1sP09V33bIEls8QMVqww2MiTshewT_AZFnfKWs1B9Z5V1VySc046HW1ZFT_0mPKMp6U62Jw&pv=2

http://s7257.chomikuj.pl/File.aspx?e=5i2nJJ6BMo2hghFeAYJMhbWEYMPhTio-NcaB02fOvKjc8VufTF4F5XgL5sOTQUai2oQVgJYLBLQUWRraNmDzzR9s3H_rUgYMtlZ7bieMKRKAZiTnpf-AeStOAxG044wcTwGTMubUFak5LOQ3NBQLXZHKBY8FtEKxFcGXgbFcXFc&pv=2

http://s7257.chomikuj.pl/File.aspx?e=5i2nJJ6BMo2hghFeAYJMhbWEYMPhTio-NcaB02fOvKjfEksi24JpNFRwzmWLxSIpp2TYJABOSz-lxkfj9ecpEy_fBHzU-0NMup8y_QRHhzykmAWZExh-uQc1RHZ3tfWx6Wgk0zv6xVGNVWdIVoduvP2_ClpR7bbn5n8iA0x6AYQ&pv=2

http://s7257.chomikuj.pl/File.aspx?e=5i2nJJ6BMo2hghFeAYJMhaRdFkkU3Sp-ZBy5GyEXcOQ-sQZOESGRplsuHGaIagMIra08WEAqbrY8aeaPNttblGeomyI2jTnBg4Nq0CbPKZXnSXBbx-bF2CBekv_mGFo_u_7SFFFkwDR5Bzlmj69bVQVQyZOqgJCyztHj0n9-08g&pv=2

Scan 2____wa_update-3.6.31.0_beta_installer.exe - Powered by Reason Core Security