avistep.exe

This is a setup program which is used to install the application.
MD5:
7729a424da94a3da066ecfc8a77f10b3

SHA-1:
d148be2386c76cf8bd4560a09cfa9f779900c190

SHA-256:
2cd61ea80c91127ed06421101ef5056a354b9bad07095693ca4fdd65c287fbcf

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
1/15/2025 4:14:08 AM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.Wpbrutebot-2
0.98/21411

File size:
2.8 MB (2,982,400 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:IkNh2Fy313nhHLB6t210AQx4n4CltQ8j6foeUhAK6raPEipDKq+PFrZxkv3WMol7:Foyl3nNLB2D44F6AKL8ixYG+

Entry address:
0x120C9C

Entry point:
55, 8B, EC, 83, C4, F0, B8, 3C, 08, 52, 00, E8, 38, 67, EE, FF, A1, 58, 34, 52, 00, 8B, 00, E8, B4, 88, F4, FF, A1, 58, 34, 52, 00, 8B, 00, BA, D4, 0D, 52, 00, E8, AF, 84, F4, FF, 8B, 0D, CC, 35, 52, 00, A1, 58, 34, 52, 00, 8B, 00, 8B, 15, B0, 91, 51, 00, E8, A3, 88, F4, FF, 8B, 0D, 38, 2F, 52, 00, A1, 58, 34, 52, 00, 8B, 00, 8B, 15, 98, FA, 50, 00, E8, 8B, 88, F4, FF, 8B, 0D, 70, 32, 52, 00, A1, 58, 34, 52, 00, 8B, 00, 8B, 15, 04, 0E, 4C, 00, E8, 73, 88, F4, FF, 8B, 0D, F0, 36, 52, 00, A1, 58, 34, 52, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.1 MB (1,179,136 bytes)

The file avistep.exe has been seen being distributed by the following 2 URLs.

temp:AviStep.exe

Scan avistep.exe - Powered by Reason Core Security