Halo - KeyGen.exe

HaloKeyGen

This is a setup program which is used to install the application. The file has been seen being downloaded from dc381.4shared.com and multiple other hosts.
Product:
HaloKeyGen

Description:
Keygenerator

Version:
1.00

MD5:
eeadf44d9bb882cd3a60bedbbca66b62

SHA-1:
b486ed90f221d78f9e346519511c3a14ee4fe1b1

SHA-256:
13bd703715cfa4a44370690791b6f4ca2f011fb41c7bad82b41e9b9ef6adf155

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/5/2024 4:45:23 AM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
not-a-virus.Keygen.halo2
t3scan.2.2.29

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.14501

File size:
244 KB (249,856 bytes)

Product version:
1.00

Copyright:
DerMönch

Original file name:
Halo - KeyGen.exe

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

File PE Metadata
Compilation timestamp:
9/28/2005 7:38:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:HhHGSLsZDA/B+CqxzS9w6lhvPRv0vu5XKUfCYS7pFP4FyGLsFrNc+h+2mppvZDns:JGSLsBgqoflDk6KM+pCg1Nc+h+lvv5z

Entry address:
0x1194

Entry point:
68, 48, 69, 43, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 2D, FC, D4, 88, 83, E3, 64, 40, AC, CD, 5A, 1B, 2D, A7, 1A, 78, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 65, 72, 53, 74, 79, 6C, 50, 72, 6F, 6A, 65, 6B, 74, 31, 00, 20, 30, 20, 20, 27, 4B, 65, 00, 00, 00, 00, FF, CC, 31, 00, 03, A7, 1C, 39, 0B, 3C, C7, 24, 41, 9C, EC, 9A, 94, E3, 30, AB, 27, 6B, 01, D4, 24, 8B, 2B, 82, 49, AC, 12, 93, F5, B6, 10, 59, E7, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
220 KB (225,280 bytes)

The file Halo - KeyGen.exe has been seen being distributed by the following 2 URLs.

http://dc381.4shared.com/download/.../Keygen_de_Halo_1.exe

Scan Halo - KeyGen.exe - Powered by Reason Core Security