aira8d0.exe

Super Backup Online Backup

Strongvault Online Storage LLC

The application aira8d0.exe, “This installer database contains the logic and data required to install Super Backup Online Backup.” by Strongvault Online Storage has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Stronghold.com  (signed by Strongvault Online Storage LLC)

Product:
Super Backup Online Backup

Description:
This installer database contains the logic and data required to install Super Backup Online Backup.

Version:
2.5.0.16

MD5:
87c5ef3ee8336a4bb911a48c31796756

SHA-1:
4a425d27a7ad6b7078f4dce7e994744aba823772

SHA-256:
eadadb6d31883dda84e9aa94f8af8f46713dcbb91133a18a3567dc8509a76bdd

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 7:49:30 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.5.20.23

File size:
15.3 MB (16,001,280 bytes)

Product version:
2.5.0.16

Copyright:
Copyright (C) Stronghold.com

Original file name:
SuperBackup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\aira8d0.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/25/2014 6:00:00 PM

Valid to:
3/27/2015 6:59:59 PM

Subject:
CN=Strongvault Online Storage LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Strongvault Online Storage LLC, L=newport beach, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
172B8010556701DF9B19141DC4772C8D

File PE Metadata
Compilation timestamp:
11/29/2012 2:50:22 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:EajRu51mX3xI6y25/om/y7u8r/p47yv+x7YawIRko+:EqRcmP5/oljr/p8yvkYy2o+

Entry address:
0x2F587

Entry point:
E8, 30, 9F, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 55, 08, 53, 56, 57, 33, FF, 3B, D7, 74, 07, 8B, 5D, 0C, 3B, DF, 77, 1E, E8, 88, 3A, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 11, 3A, 00, 00, 83, C4, 14, 8B, C6, 5F, 5E, 5B, 5D, C3, 8B, 75, 10, 3B, F7, 75, 07, 33, C0, 66, 89, 02, EB, D4, 8B, CA, 0F, B7, 06, 66, 89, 01, 41, 41, 46, 46, 66, 3B, C7, 74, 03, 4B, 75, EE, 33, C0, 3B, DF, 75, D3, 66, 89, 02, E8, 3F, 3A, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, B3, 8B, FF, 55, 8B, EC, 83, EC...
 
[+]

Entropy:
7.9735  (probably packed)

Code size:
268.5 KB (274,944 bytes)

Remove aira8d0.exe - Powered by Reason Core Security