installer.exe

The executable installer.exe has been detected as malware by 8 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.capitalsendhost.com.
MD5:
d210a2794d20730111bb0db26c36dc53

SHA-1:
e36c55ac7ce638c232eae993642d1c9419b1bf5e

SHA-256:
3e0eec6d454b62118ad24792bc6a2a50515a1354eda00f4a08948c7d854bd46e

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
12/27/2024 2:06:43 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160126-1

AVG
Win32/Sality
2015.0.4489

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

McAfee
Trojan.Artemis!DF0F371385C5
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.5231.0

Norman
Win32.Sality.3
03.02.2016 10:30:35

VIPRE Antivirus
Threat.4758034
46800

File size:
268 KB (274,432 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\installer.exe

File PE Metadata
Compilation timestamp:
1/28/2016 4:39:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:I32QfhLL+R539B1dQygIQ6UxEPUYoEZM8:I32QJn+R5NvFUx4gEm8

Entry address:
0x26951

Entry point:
81, FA, 38, 62, 00, 00, 72, 06, F7, C6, 63, E1, 05, 3B, 76, 0C, 86, F2, 8D, 35, 93, FC, 02, 22, FF, C3, 84, CC, 69, DF, CB, 3C, 5E, 3D, 84, CD, 8D, 15, 52, 33, FB, B6, 81, F5, C2, C5, 00, 00, BE, 0C, C4, 47, 89, 0F, B7, CB, 8D, 1D, 08, 2F, 2E, BC, 52, 52, 0F, AF, C9, E8, 22, 00, 00, 00, F7, C7, 60, 3A, 51, 6D, 08, E7, F6, C2, 0C, 78, 09, F6, DA, 42, 81, DE, D9, D6, 4E, 92, 8D, 45, 00, 69, D6, 49, B1, 04, 25, 8D, 28, 49, 69, F0, FD, 7D, E1, 82, 81, FE, 16, C1, 00, 00, 71, 04, 87, CE, F7, D1, F6, DB, 3B, D7...
 
[+]

Entropy:
7.6428

Code size:
176 KB (180,224 bytes)

The file installer.exe has been seen being distributed by the following URL.

Remove installer.exe - Powered by Reason Core Security