installer.exe

The application installer.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.giftdownloadscycle.com.
MD5:
e15d6d715fdc101b1a6b2619ed674ab7

SHA-1:
ad813f0839afbec8402ec0b5e7027a9e9b68823a

SHA-256:
e40879e72ee3853c8b23ade7494459d952fd58cc644e9706ee3fbe92fc3c5292

Scanner detections:
9 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 2:12:57 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160205-0

AVG
Win32/Sality
2015.0.4489

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Program.Artemis!F2C31D1FAE70
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.5580.0

Norman
Win32.Sality.3
03.02.2016 10:30:35

VIPRE Antivirus
Threat.4721115
46904

File size:
268 KB (274,432 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\installer.exe

File PE Metadata
Compilation timestamp:
2/2/2016 10:45:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:VbwjDqMvnL9NFOeX09C7E3mIqGYjee86gUMxycvUpHiNAwCedBv7:VbwjGoLB7AC7E3mnGMPgFyCURcAw7jj

Entry address:
0x25EEE

Entry point:
EB, 07, 18, F3, 0F, BE, C3, 85, D0, 0F, BF, D2, F3, B9, 15, 13, 82, EA, F6, C6, 3C, 87, F2, 88, D0, 03, CB, BB, 79, EA, 5D, DF, 89, EE, 8D, 1D, 3D, A3, B1, D6, F6, C3, D8, 33, DB, 43, 85, F8, BF, 93, 27, DF, 77, 0A, C4, F3, 81, FB, 84, 06, 00, 00, 0F, 86, E9, FF, FF, FF, 08, F9, 0F, B7, D6, 84, E6, 71, 0E, FF, C9, 69, FB, 56, C0, DC, 90, 69, D3, 8A, BA, 55, B3, E8, 3B, 00, 00, 00, 80, C2, 80, 69, C8, 58, A0, A7, 46, C7, C0, 76, 15, 63, B5, C7, C7, 43, CF, D4, C5, 8D, 0D, A9, 71, 64, 00, 2C, F2, F2, 01, C8...
 
[+]

Entropy:
7.6040

Code size:
176 KB (180,224 bytes)

The file installer.exe has been seen being distributed by the following URL.

Remove installer.exe - Powered by Reason Core Security