Battlefield Hardline InstallShield.exe

Battlefield Hardline

This is a setup program which is used to install the application. The file has been seen being downloaded from 51.255.39.248 and multiple other hosts.
Product:
Battlefield Hardline

Version:
1.0.0.1

MD5:
e72f8cf293cee1c64c3346889a9e0cf9

SHA-1:
d56661b2fa1c4059175dc2bd21c1aee9a354d60f

SHA-256:
088b6f5c0daa0176be3e347da21ba7b5370ce4a7d3969727ff79022185c5ea32

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/15/2024 12:27:05 PM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1120

File size:
3 MB (3,170,304 bytes)

Product version:
1.0.0.1

Original file name:
Battlefield Hardline InstallShield.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\battlefield hardline installshield.exe

File PE Metadata
Compilation timestamp:
1/9/2016 4:52:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:nw3oPqS4UqygI4Z5rJKGgWPzD61/GgWPzD6aDbY77BaAhnmYPLDrB/bp5FDbd:nw3oPr4NbJfH6CH6aDU77BtPXd/ZD

Entry address:
0x2B51CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AE, 2C, 91, 56, 00, 00, 00, 00, 02, 00, 00, 00, 1C, 01, 00, 00, 1C, 60, 2B, 00, 1C, 36, 2B, 00, 52, 53, 44, 53, B4, A1, 47, 62, CD, FD, F5, 42, A3, 76, 80, 4F, EE, CA, EF, FD, 01, 00, 00, 00, 45, 3A, 5C, 50, 72, 6F, 6A, 65, 6B, 74, 5C, 42, 61, 74, 74, 6C, 65, 66, 69, 65, 6C, 64, 20, 48, 61, 72...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.7 MB (2,830,848 bytes)

The file Battlefield Hardline InstallShield.exe has been seen being distributed by the following 2 URLs.

http://51.255.39.248/Jeux/.../Battlefield Hardline InstallShield.exe

Scan Battlefield Hardline InstallShield.exe - Powered by Reason Core Security