buildtoolsgui.exe

BuildTools

Product:
BuildTools

Version:
1.0.0.0

MD5:
6444b5ef3456d3aaf466b0ec7c09e272

SHA-1:
d399286a4217d3a055e9b0923aeb251d6e1e8796

SHA-256:
48e9557a2b6bd6ee2bc776478be6f58c8909d59e1bc488f399fc83e9ef4c63fb

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/25/2024 6:49:53 PM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

File size:
1.1 MB (1,157,632 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Kyle Wood (DemonWav) 2015

Original file name:
BuildTools.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\buildtoolsgui.exe

File PE Metadata
Compilation timestamp:
4/17/2016 8:38:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:fvCi6SvKhs50FQ/EEW0D8bnmS4mshe+e6Kfm/NYNY9LaDKKGSBTV9Wdee:fviyhIP4mh5fO/WG9LaDKfSBTV9Wke

Entry address:
0x11B1BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 60, 00, 00, 80, 10, 00, 00, 00, 90, 00, 00, 80, 18, 00, 00, 00, C0, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.2465

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.1 MB (1,151,488 bytes)

The file buildtoolsgui.exe has been seen being distributed by the following 4 URLs.

https://www.spigotmc.org/cdn-cgi/.../chk_jschl?jschl_vc=e12d023a5759aa32349f000441a88198&pass=1483088237.902-BFS Y2rrsC&jschl_answer=99695

https://www.spigotmc.org/resources/.../download?version=84808

Scan buildtoolsgui.exe - Powered by Reason Core Security