HeinInstaller.exe

Hein

This is a self-extracting archive and installer. The file has been seen being downloaded from download2227.mediafire.com and multiple other hosts.
Publisher:
Hein

Version:
2.0.0.0

MD5:
80903a9f3aaa54c7b7ee5ce744e8aeaf

SHA-1:
b3c31be3e9bf55f1ef37a056d0ef44ff46ca50de

SHA-256:
b48e92dde14589ba2d7acbc8165afd81f8701dbbecbbe55f454855c70deec127

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/26/2024 12:43:13 PM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
Malware.RDM.08!5.E
23.00.65.16602

File size:
1.6 MB (1,626,112 bytes)

Copyright:
Hein

Original file name:
HeinInstaller.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\heininstaller.exe

File PE Metadata
Compilation timestamp:
2/8/2016 4:55:16 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:QwzCzEPkM260aVn0Pv/A5UxO6B4ffxfap:9POaV+HA5UtB4fQp

Entry address:
0x1611

Entry point:
E8, AD, 17, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 00, FF, 40, 00, E8, 49, 1D, 00, 00, E8, 7E, 19, 00, 00, 0F, B7, F0, 6A, 02, E8, 40, 17, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, CE, 02, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
41.5 KB (42,496 bytes)

The file HeinInstaller.exe has been seen being distributed by the following 3 URLs.

http://download2227.mediafire.com/49cj3862tpbg/.../HeinInstaller.exe

http://download2227.mediafire.com/sjxj499w7dwg/.../HeinInstaller.exe

Scan HeinInstaller.exe - Powered by Reason Core Security