digitaltextbook.exe

ALZip

ESTsoft Corp.

This is a setup program which is used to install the application. The file has been seen being downloaded from file.st.edunet.net.
Publisher:
ESTsoft Corp.

Product:
ALZip

Description:
ALZip Self Extractor

Version:
12, 6, 11, 0

MD5:
91f3746534f6540164e1934d1bc30562

SHA-1:
4aab023f4d2a42e5e4b59928cdd578ca6874c115

SHA-256:
281b143aedb30270d14d22c42010817d8500128c5966f2b17af575e6dc1a5182

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/23/2024 5:33:59 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.DR.Dapato
7.1.1

NANO AntiVirus
Trojan.Win32.Genome.brkhbz
0.30.10.952

File size:
83.6 MB (87,694,586 bytes)

Product version:
12, 6, 11, 0

Copyright:
Copyright (c) 1999 - present ESTsoft Corp. All right reserved.

Original file name:
EGGSFX.sfx

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\digitaltextbook.exe

File PE Metadata
Compilation timestamp:
6/11/2012 8:33:03 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1572864:qB6x5JX+jYSxcHmDLJZf/iuuBY11TJZU97W/7Zg6itT6HL8gZ/8WitiW0a:qMxMFDLOhBI1TJZ67WqTgzZEWwma

Entry address:
0x34BDF

Entry point:
E8, 29, 96, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 10, 00, 75, 04, 33, C0, 5D, C3, 8B, 55, 0C, 8B, 4D, 08, FF, 4D, 10, 74, 13, 0F, B7, 01, 66, 85, C0, 74, 0B, 66, 3B, 02, 75, 06, 41, 41, 42, 42, EB, E8, 0F, B7, 01, 0F, B7, 0A, 2B, C1, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, 53, 56, FF, 75, 10, 8D, 4D, F0, E8, 7E, E3, FF, FF, 8B, 5D, 08, 33, F6, 3B, DE, 75, 2F, E8, BA, FC, FF, FF, 56, 56, 56, 56, 56, C7, 00, 16, 00, 00, 00, E8, 49, DB, FF, FF, 83, C4, 14, 80, 7D, FC, 00, 74, 07, 8B, 45, F8...
 
[+]

Entropy:
7.9993  (probably packed)

Code size:
288 KB (294,912 bytes)

The file digitaltextbook.exe has been seen being distributed by the following URL.

Scan digitaltextbook.exe - Powered by Reason Core Security