installer.exe

The executable installer.exe has been detected as malware by 10 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from www.appsgrabnow.com.
MD5:
d5c9ca0bc911bb934fb3966a4511de08

SHA-1:
7c7e0f7238e7e7a41c6c63cf6e4cae80cb03a445

SHA-256:
09abda63a30dd3ff601f2fe10778bf5f14f55c1012197fd3775f2f864af4b3a6

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/24/2024 5:36:11 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160215-2

AVG
Win32/Sality
2015.0.4533

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Trojan.Artemis!F7A3E4C5039D
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.846.0

Norman
Win32.Sality.3
29.02.2016 05:46:54

File size:
452 KB (462,848 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\installer.exe

File PE Metadata
Compilation timestamp:
1/12/2016 10:06:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:FBiPhoLa0IOfDfZuCHCRJSe5fQgpSUaEw1e6+J3lN6iL:FQoLaLOfDoCHmS+fQhUsfa3lYiL

Entry address:
0x5379F

Entry point:
EB, 0D, B8, 9E, 42, E6, 12, 89, F9, 8D, 1D, AB, 30, 26, 4E, 0F, AF, ED, F6, C2, 2C, 0F, B7, E8, 19, D3, 01, E8, 88, D8, 81, F9, 11, 1E, 00, 00, 8D, 1D, 35, 96, 08, 11, 47, 0F, B6, C4, 74, 02, 1B, F5, B7, 26, 0F, AF, E8, 89, F1, 0F, BF, CB, 0F, B6, DC, 8D, 05, F6, 0E, 00, 00, 41, BF, 81, 25, 18, A5, EB, 01, 45, 22, D2, F3, 69, EE, 45, 54, E9, BA, 0B, F0, 85, F9, 2D, 9A, 0B, 00, 00, 69, FE, DD, B1, 37, 95, 29, D7, 05, 99, 0B, 00, 00, 20, DB, 20, EA, B3, E6, 84, C3, 3D, 50, 01, 00, 00, 0F, 85, CB, FF, FF, FF...
 
[+]

Code size:
356 KB (364,544 bytes)

The file installer.exe has been seen being distributed by the following URL.

Remove installer.exe - Powered by Reason Core Security