3e-allelesabo.exe

3e-alleles

This is a setup program which is used to install the application. The file has been seen being downloaded from wwwppeda.free.fr and multiple other hosts.
Product:
3e-alleles

Version:
1.00

MD5:
051b1bfdb838e61581f7e3e0fc974362

SHA-1:
1c3547add899612cd3cbaf5708d5c2a6055209bd

SHA-256:
e8ad1c733bd301fa22dc013c929ba6aa7ec59876e14b004afcbbbfeaf78f6bd6

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/24/2024 10:00:36 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.4959

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.141218

File size:
117 KB (119,808 bytes)

Product version:
1.00

Original file name:
3e-alleles.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
10/3/2002 12:28:57 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
4.20

CTPH (ssdeep):
3072:AgGNn0YTBHNe/XDvy51elkkPAEzw7s5L3:ALN0YWDvSHkI8l3

Entry address:
0x1130

Entry point:
68, 14, A6, 41, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, C4, 8F, 78, D1, 3B, A4, 73, 46, BD, 66, 84, E2, BF, F8, 9C, D7, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 01, 00, 0A, 00, 00, 00, 50, 72, 6F, 6A, 65, 63, 74, 31, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 10, EE, 6E, 2B, D2, 41, 16, 43, 43, A2, E7, 80, 0A, 45, D5, 5D, 98, A4, 93, C3, 14, FD, E1, C8, 4D, 96, 35, B8, 68, A3, BD, 15, 44, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
7.7362

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
110.5 KB (113,152 bytes)

The file 3e-allelesabo.exe has been seen being distributed by the following 3 URLs.

http://wwwppeda.free.fr/.../3e-allelesABO.exe

http://www.vivelessvt.com/wp-content/uploads/2009/.../3e-allelesabo.exe

Scan 3e-allelesabo.exe - Powered by Reason Core Security