installer_r24.1.2-windows.exe

$(^Name)

Google Inc.

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
Google Inc.

Product:
$(^Name)

Version:
1.16

MD5:
a5daaa500c6696dba7019aa9fe05fac3

SHA-1:
e0ec864efa0e7449db2d7ed069c03b1f4d36f0cd

SHA-256:
bc97459a11ef72a4525e5d3cd3bfd6ff7c743300aff42adab82128b6eeecd429

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 11:23:54 PM UTC  (a few moments ago)

File size:
106.2 MB (111,364,285 bytes)

Product version:
1.16

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\installer_r24.1.2-windows.exe

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3145728:IEFpptNeg5IOiLnEh877vIyPkuatF5/+pLVbJj3E/IC:IIIgyOt877hcuaj5eLVbJDEAC

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9999

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_r24.1.2-windows.exe has been seen being distributed by the following 5 URLs.

http://dw.uptodown.com/dwn/g1QCyjyyNe34WdBuJtEnC_F9U5jyf8z3bMje4HBzgyL6k6XVMdpp2qkYXGMIu9zqU87iUHnLlSrraG9bRAkMyw30iDmE9lspYYKiz9OnKYYWSt8cB5UX6cQJ8gnoDCnX/O1HGM3GZJnZ4cZhA5HlF_Jms34mlQ7jDyqqVqF6uI8JlSbW70zeri4JoVnUAgAMBST3L4pGVUETJg7DSHDaGYqZAUWrGaHNxOk0p88tfpelm2EFqgXAUwL0umsOII-a2/7VvTazx0fMsWyTAOJpKVu6RNhNjuFz9PyLs59-0TIDW7ps31f0J8VxTtjA7ewRB9gy-z8JjRTecjscWMhcSicm2Xr1-emkViSgY1tWpAyTKLWdLKXGHpKjTMxaONwFO4/.../

https://dl.google.com/.../installer_r24.1.2-windows.exe

https://dw.uptodown.com/dwn/E-JArFkkpcI3ihCvuDr3YNWHOyUg8QZeNpIlGTTsSX73XZazwegPdciCZDqZyGfdZaZsSvyNme9FGWz5Jztq9OMfqwINQtQJeIi5yvU9JOK1xcTZVgMZqYyeOE8qiucK/KeIT1IMX_XIMKSPo_j5Yd39TGzQmMAD1U6ipDYIj0SvCZRn15L3q-XEnNvljWm6X0iqRBNV4TMq1qfF6MucRNumbDBAbM8KppC-jPMoqp6EAuC_9Q-QbY5cSiAHFxZWx/EdBbRRkXNogPW6E2G789HYRZ1dBNA9uRYvJOlJA_TiqzlWmVA899lsCmKMPsHmZfhgaCxDMtvuVmGKt8qr_R3VZUd3gMftgLsgqDMc6VxcHLEjWhQ-t9pf_fUrjWUXF9/.../

Scan installer_r24.1.2-windows.exe - Powered by Reason Core Security