installer.exe

The executable installer.exe has been detected as malware by 4 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.sendcityapps.com.
MD5:
be4e47ee0df061588fbc1cedd355c819

SHA-1:
fd9b4b614005f20430adb3a83e166f177f56e525

SHA-256:
1ce2230771a44857e50d64e44133058af0c31d11aab9f7f8e49ec80d8a5823b6

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
12/27/2024 1:22:24 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Parite
160518-2

ESET NOD32
Win32/Parite.B virus
8.0.319.0

F-Prot
W32/Parite.B
4.6.5.141

VIPRE Antivirus
Threat.46249
50318

File size:
662.5 KB (678,360 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\installer.exe

File PE Metadata
Compilation timestamp:
12/27/2015 3:38:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:8IaMnnQ+lCshIVnx3Y3emTLgY+sJ4iLu7ttAl2QuhOb1SCc9l1484FMa4j:8RsnQ+4tVneX+sJFLuxcduhGICcHgF0

Entry address:
0x38000

Entry point:
90, 90, 68, AE, 82, 14, F8, 5B, 90, 90, BF, 1E, 80, 43, 00, 68, 98, 05, 00, 00, 5E, 90, 90, 31, 1C, 3E, 83, EE, 03, 4E, 90, 75, F6, 90, 46, FF, 15, F8, AE, 82, 14, F8, AE, 82, 54, F8, A3, B3, 14, F8, 8C, 20, 13, F8, 76, 2B, 13, F8, AE, 32, 16, F8, AF, 82, 14, F8, CA, F2, 54, F8, 90, F8, 54, F8, 16, FB, 54, F8, 72, EB, 14, F8, 92, F8, 14, F8, 18, FB, 14, F8, CA, E6, 14, F8, 92, F8, 14, F8, 18, FB, 14, F8, AE, 82, 14, F8, AE, 82, 14, F8, AE, 82, 14, F8, AE, 82, 14, F8, 7A, F2, 54, F8, AE, 82, 14, F8, AE, 82...
 
[+]

Code size:
24 KB (24,576 bytes)

The file installer.exe has been seen being distributed by the following URL.

Remove installer.exe - Powered by Reason Core Security