dsj 3 1.5.0.exe

Mediamond Tmi

The executable dsj 3 1.5.0.exe, “Deluxe Ski Jump 3 Setup ” has been detected as malware by 10 anti-virus scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from s6591.chomikuj.pl.
Publisher:
Mediamond Tmi

Description:
Deluxe Ski Jump 3 Setup

Version:
1.5.0.0

MD5:
5a4b7db66a14c83c9308989decaec81c

SHA-1:
7dccc415ed2dedafdbe6b8eb5b08e3efc85f1dee

SHA-256:
4d7cb90a21485d639f49d0bd9aa2f197d20c99124223e176de6dc4724ccc7cba

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/25/2024 10:24:05 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
150717-0

AVG
Win32/Sality
2015.0.4355

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.217.1571.0

Norman
Win32.Sality.3
10.04.2016 15:29:17

File size:
3.7 MB (3,905,088 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
English (United States)

Common path:
C:\documents and settings\andrzej\moje dokumenty\downloads\dsj 3 1.5.0.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:5VDvLWHoCxq/x7Kc3eLyBHM+mOIoWRqyMOUH:HDDWHoUY6Gs+BHCqyMOq

Entry address:
0x98D8

Entry point:
0D, 51, CB, 43, 26, 8D, 0D, 37, 45, 44, 06, 29, FD, F2, 0F, AF, D0, 1C, DB, 38, E9, 0F, B6, F3, FF, CA, B8, 9E, 45, 8C, B3, 0F, AF, C5, 86, D3, F2, 81, F7, D1, D3, 00, 00, 38, E3, 88, C4, 81, C0, 99, 61, 46, AE, 0F, B6, ED, 70, 04, 85, CD, 14, 6E, 81, F5, 1A, EB, 06, F3, C6, C4, 09, 25, E2, 0E, 7E, AE, F3, FF, CE, E8, 17, 00, 00, 00, 85, FF, 78, 04, 86, F6, 86, C9, 81, FE, 1F, AD, D8, F9, 09, F2, 08, C3, C6, C2, 1F, 3B, C3, 69, FF, DD, 6A, 80, 50, 4A, 0F, B7, CA, 0F, B7, C6, 78, 06, 89, FF, 8A, F0, 3A, F7...
 
[+]

Code size:
36 KB (36,864 bytes)

The file dsj 3 1.5.0.exe has been seen being distributed by the following URL.

Remove dsj 3 1.5.0.exe - Powered by Reason Core Security