inglaterra2015.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from s8229.minhateca.com.br and multiple other hosts.
MD5:
46acf6663a7d2cea1d3bc554ffe8a2d0

SHA-1:
ea9e227ae79992d174136a789c95dbcf7cf9557e

SHA-256:
a67618d9a062a4d02a677e510d6263c7456e41343aaa76a1f31e7418ef564c0d

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/25/2024 7:07:18 PM UTC  (today)

Scan engine
Detection
Engine version

NANO AntiVirus
Trojan.Win32.GBZG0066.dtleie
0.30.24.2487

SUPERAntiSpyware
Trojan.Agent/Gen-Agent
9765

File size:
1 MB (1,049,298 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\programs\inglaterra2015.exe

File PE Metadata
Compilation timestamp:
10/7/2014 1:40:23 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:5UkRs6DIWMJcknfV3Erh+ZX5i1A9DDNE6:5UGs6zIN3PjkAt

Entry address:
0x30E2

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, 78, E4, 42, 00, E8, A8, 2D, 00, 00, A3, C4, E3, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 00, 88, 42, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, C0, DB, 42, 00, E8, 52, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 40, 43, 00, 50, 55, E8, 40, 2A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file inglaterra2015.exe has been seen being distributed by the following 31 URLs.

http://s8229.minhateca.com.br/File.aspx?e=REUKnZWIjqFca09vwRecL5iCaPlhlSbWEHEl8WGhPMfb5-RpUPVHQIVhxR4Vu2xm-FCmqBwawbtgkF0WeqvNx6pCSB0x19r5tD4gfoigscxwyWXfclZxwFmAW3xF3a5sgJxz0BFaWBYufBpYwsYYSg&pv=2

http://s8240.minhateca.com.br/File.aspx?e=REUKnZWIjqFca09vwRecL5iCaPlhlSbWEHEl8WGhPMeLLTE75JdtWZbdCi9aw6EE0fJGpV7JdnS4askbe5I55m0OVtJpo9vMDBnIekTYcH7yqYbhl-oKkRR_EvuI1jC3wsgGmQ1w9R_BlwxrrRYBnA&pv=2

http://s8240.minhateca.com.br/File.aspx?e=REUKnZWIjqFca09vwRecL5iCaPlhlSbWEHEl8WGhPMc5gNrkt0_UkhVqEAX7r33QjYSUE0x0cRTIBluFZXzAUxAzxRMGmdyi3Bym30Xdsrjojy75sGmWtYUFzY5rWRJNw9y75cFp9ap4g8uZMLACcQ&pv=2

http://s8229.minhateca.com.br/File.aspx?e=REUKnZWIjqFca09vwRecLw30sAYoPZcHBMOJvkFh0_2fGGmmXsk4KB9mF1X6VLVnc32YRPN5ALiepkMgUJ8wgylWnlUmuYY_iKVX-zFKrSNVnhEPpFNO95iAqOJHppsWTN-vBz4uwREGSzK3_t3UWQ&pv=2

http://s8240.minhateca.com.br/File.aspx?e=REUKnZWIjqFca09vwRecL5iCaPlhlSbWEHEl8WGhPMehanq0h6SdKtNi0I2uvyyiXB_o1BMbxwMh8AhzqD5VZL1FT9O49VLL5Laz9UR59_I0bMx5XN7MAPqG7MQ1tbBjMcg3yUD-9tqHbZE4WpIMng&pv=2

http://dc743.4shared.com/download/.../inglaterra2015.exe

http://s8240.minhateca.com.br/File.aspx?e=REUKnZWIjqFca09vwRecL5iCaPlhlSbWEHEl8WGhPMdoCTYo8r9T-6E1X475hWFaDnD_b0-cc0VnEn09Wl1r6MbfFIokpwM-NHny2YdMVg44ANT0ho7oRf7cJtlktUXvLD-nGF2C4oBi42ywRnWZUA&pv=2

Latest 30 of 31 download URLs

Scan inglaterra2015.exe - Powered by Reason Core Security