crear portables vip.exe

Michal Kokorceny

Publisher:
74.cz  (signed by Michal Kokorceny)

Description:
Make SFX

Version:
2.8.18.58

MD5:
cb43b7a7ef532e0a1dd1e46e294a49ec

SHA-1:
d4841e0189bf77028dc6681cc85fc9c977602997

SHA-256:
1cc3e329e093205f2bd3cfed3fb84a5a56617fcc2d0a80525797e260686c54ea

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/27/2024 1:49:52 PM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Malware.RivalGame!6.347
23.00.65.15713

File size:
483.2 KB (494,832 bytes)

Product version:
1.0.0.0

Copyright:
Freeware

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\vip softwares\crear portables vip.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
5/26/2009 7:00:00 PM

Valid to:
5/27/2010 6:59:59 PM

Subject:
CN=Michal Kokorceny, O=Michal Kokorceny, STREET=Evropská 694/18, L=Praha 6 - Dejvice, S=Czech Republic, PostalCode=16000, C=CZ

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
008FCEDA83430F8767730B86654D0D891B

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:877djw5hLZLMaKidpY7osC7XjIwBKcNk0:875GLMXibjXkwtZ

Entry address:
0x592DC

Entry point:
55, 8B, EC, 83, C4, E4, 33, C0, 89, 45, EC, 89, 45, E8, 89, 45, E4, B8, BC, 90, 45, 00, E8, A1, D5, FA, FF, 33, C0, 55, 68, FB, 93, 45, 00, 64, FF, 30, 64, 89, 20, B8, 10, 94, 45, 00, E8, D9, 47, FB, FF, 8B, 15, F0, AF, 45, 00, 88, 02, B8, 1C, 94, 45, 00, E8, C7, 47, FB, FF, 34, 01, 8B, 15, C8, B2, 45, 00, 88, 02, B8, 28, 94, 45, 00, E8, B3, 47, FB, FF, 8B, 15, 14, B3, 45, 00, 88, 02, E8, 52, C7, FF, FF, 83, F8, 03, A1, 58, B0, 45, 00, 0F, 9D, 00, A1, 14, B3, 45, 00, 80, 38, 00, 74, 48, A1, 58, B0, 45, 00...
 
[+]

Entropy:
6.5682

Developed / compiled with:
Microsoft Visual C++

Code size:
353.5 KB (361,984 bytes)

The file crear portables vip.exe has been seen being distributed by the following 5 URLs.

https://mega.nz/temporary/.../KBtgyKDB

http://gsf-cf.softonic.com/d48/41e/.../file?SD_used=0&channel=WEB&fdh=no&id_file=83357&instance=softonic_es&type=PROGRAM&Expires=1476258092&Signature=L0c0PPomoH6PPIVApjQOG1KYfxkfWkjgIM01-nh~rPlLc92jC7H3utcB6Sw4fHF~CpPFW2zuyhMyWBXd~mkISDsem4Z-dBGz5jB8WY9REI~~9h-Rqq9tD6zBgzV7KKRHpoAJ5mz4Sb~3XumZHMbM6M~mar5vo7QIgfrk66O1SfE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=makesfx.exe

http://gsf-cf.softonic.com/d48/41e/.../file?SD_used=0&channel=WEB&fdh=no&id_file=83357&instance=softonic_es&type=PROGRAM&Expires=1467077035&Signature=ZLAJq5IUNeSqrdaLqw7-RmIxA9LHpi-vIay7D7L30YI~Sp3N4HDeOsUgOOEdrn3xVrcZ2Ec6u~qCuqsgKmBn4-k4wVr41r0RqqXTHEx3k2IcqyP5jA8PX7QzPeNxYZONfOArye2OtJqUnSZoQpLKLJINBhmLXlXadVfgxUfozXE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=makesfx.exe

Scan crear portables vip.exe - Powered by Reason Core Security