iw3sp.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from download1141.mediafire.com and multiple other hosts.
MD5:
77d460bfbfff90bcf930ecc654588000

SHA-1:
5e822a6a5e97a94db0ac2c521bfaaf7cc19c49c2

SHA-256:
d07c39ee5865972a319a4a174be6134c59911f34fa9ebbafb815674af7d3e116

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 10:14:14 AM UTC  (today)

File size:
2.9 MB (3,017,216 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
10/4/2007 3:23:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:YZO5n7dunt+gkU8RaLmrcTvLs+FR9gVYAuysCCHAOZNhGebsVTNWdkFppGnf9/wh:YZO5n7dut+gCRaLLTvLs+FLgVYjyXCHy

Entry address:
0x2434C1

Entry point:
E8, 7F, 90, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 83, EC, 08, 89, 7D, FC, 89, 75, F8, 8B, 75, 0C, 8B, 7D, 08, 8B, 4D, 10, C1, E9, 07, EB, 06, 8D, 9B, 00, 00, 00, 00, 66, 0F, 6F, 06, 66, 0F, 6F, 4E, 10, 66, 0F, 6F, 56, 20, 66, 0F, 6F, 5E, 30, 66, 0F, 7F, 07, 66, 0F, 7F, 4F, 10, 66, 0F, 7F, 57, 20, 66, 0F, 7F, 5F, 30, 66, 0F, 6F, 66, 40, 66, 0F, 6F, 6E, 50, 66, 0F, 6F, 76, 60, 66, 0F, 6F, 7E, 70, 66, 0F, 7F, 67, 40, 66, 0F, 7F, 6F, 50, 66, 0F, 7F, 77, 60, 66, 0F, 7F, 7F, 70, 8D, B6, 80, 00, 00, 00, 8D, BF...
 
[+]

Code size:
2.4 MB (2,498,560 bytes)

The file iw3sp.exe has been discovered within the following programs.

Call Of Duty 4  by Activision
Call Of Duty 4 is a PC video game published by Activision.
www.Activision.com
6% remove it
www.GIGAPCGAMES.com
About 6% of users remove it
Call of Duty: Modern Warfare 2 is a first-person shooter video game developed by Infinity Ward and published by Activision. The player assumes the role of various characters during the single-player campaign, changing perspectives throughout the progression of the story.
www.modernwarfare2.com
9% remove it
Call of Duty 4: Modern Warfare is a first-person shooter video game, developed by Infinity Ward and published by Activision.
www.activision.com
5% remove it
 
Powered by Should I Remove It?

The file iw3sp.exe has been seen being distributed by the following 50 URLs.

http://download1141.mediafire.com/7tooacbafh9g/.../iw3sp.exe

http://download1715.mediafire.com/35am226l51mg/.../iw3sp.exe

http://download2215.mediafire.com/3hred1avsrwg/.../iw3sp.exe

http://download2215.mediafire.com/6ptwdcmst1jg/.../iw3sp.exe

http://download1715.mediafire.com/umupjj2tv4cg/.../iw3sp.exe

http://download2079.mediafire.com/uyej14m7m9fg/.../iw3sp.exe

http://download2215.mediafire.com/qwwy3wwta1fg/.../iw3sp.exe

http://download2215.mediafire.com/cz834roma0mg/.../iw3sp.exe

http://download2215.mediafire.com/1w3pie8sk2pg/.../iw3sp.exe

http://172.27.27.248/2TB1/games2//index.php?dir=Call of duty 4 [PC-DVD] [English]/.../&file=iw3sp.exe

https://mega.nz/temporary/.../Fl5WmQgL

http://fileshare1290.depositfiles.org/auth-1476026593f0db31ad6694f9f2c5eb0d-186.95.5.241-7099982-112355890-guest/.../iw3sp.exe

http://download1715.mediafire.com/ft4y5ccta4cg/.../iw3sp.exe

http://fileshare1290.depositfiles.org/auth-1433809617269083482f8722bb3d4a76-179.179.242.138-2103548360-112355890-guest/.../iw3sp.exe

http://fileshare1290.depositfiles.org/auth-14782195084d2d2bc27e82852e353940-181.58.28.86-29563754-112355890-guest/.../iw3sp.exe

http://download1443.mediafire.com/z1bao4hb9fcg/.../iw3sp.exe

http://ddl3.data.hu/get/0/.../iw3sp.exe

http://download1264.mediafire.com/651l19xnxifg/.../iw3sp.exe

http://download1141.mediafire.com/qowoe529ycyg/.../iw3sp.exe

https://drive.google.com/uc?id=0B3ETFN1fWu8weGc3MVJnUUdNOTQ&export=download

http://download2215.mediafire.com/e2w98r7i3ikg/.../iw3sp.exe

http://download2215.mediafire.com/4c1swlr6r7vg/.../iw3sp.exe

http://download833.mediafire.com/tz5pfb5latjg/.../iw3sp.exe

http://download1290.mediafire.com/1g2baq3iackg/.../iw3sp.exe

http://download2215.mediafire.com/hxr8vbu4g4vg/.../iw3sp.exe

http://download2215.mediafire.com/r952cp8ycczg/.../iw3sp.exe

http://fileshare1290.depositfiles.com/auth-1465000460ef983fd6d29fe6b1798cc2-200.77.96.26-2583161997-112355890-guest/.../iw3sp.exe

Latest 30 of 51 download URLs

Scan iw3sp.exe - Powered by Reason Core Security