magic_partition_recovery.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from t1.softonicads.com and multiple other hosts.
MD5:
3d068d9b0cb2f392ae9e9aa824172cf1

SHA-1:
bd5205c601f516a088f0df0d1cd56f059ac521b4

SHA-256:
fcc79767e98057f0db3decfbfa0dfe8229349bb81b2670b7af5814d437f46766

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/27/2024 2:53:07 AM UTC  (today)

Scan engine
Detection
Engine version

Zillya! Antivirus
Trojan.Kryptik.Win32.807709
2.0.0.2554

File size:
13.7 MB (14,397,577 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\nueva carpeta \magic_partition_recovery.exe

File PE Metadata
Compilation timestamp:
2/24/2012 2:19:54 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:Z3iNR/LMYdEzQBNG5H2KqK1qS8wYQVoJt4U:BApyzQHGAKj8wxA4U

Entry address:
0x3883

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, 92, 40, 00, FF, 15, 84, 81, 40, 00, 68, 4C, 92, 40, 00, 68, C0, AD, 46, 00, E8, 18, 27, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
27.5 KB (28,160 bytes)

The file magic_partition_recovery.exe has been seen being distributed by the following 14 URLs.

http://t1.softonicads.com/tracker.php?ev=c&co=DZ&sid=3e72a174bbd08f8d682c3243e4163b43&upv=6e5cbedbdd46376f450f46ec383eb4fc&z=results&sk=0&abp=0&params=32BFEDE632474BF73FB6571EF67B57F43C4B2CE9CADEC151C6982ED91B896EB70EA1A32B8F98120DD5961245CA13EA211F25EDF74F46102913F91169601FE031A967F438D8B1C737A702502F41463E32DCFBA1BAF950B07A2FF647EC8B0782DB7290EFED46D3BBF789ADF3CC0F2A034241E40A86294641FE149FCEBAE7C49F7ADB43212316D98A2249B65AB1A9ADB5D5863E52913051F963F7386E6AF1E39B62&h=A5175F18489A5E1F6024A6A3E0271CC6864A64C8252DA1E6B19E7C5613EC42A4&directdownload=1&f=3340815&d=http://www.magicuneraser.com/.../Magic_Partition_Recovery.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=CO&sid=a07a22212144041ba27847fdab41cb21&upv=c7420034468a0e931a7bce8e2bf5c271&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAE1A16743FECF3EECEB4DC3D7B3E7AEFB73F2ED3B170DB1A6DF715318E1CA89EB77F6F219C6988DD0EC1F368B275886F8079ACE7E48781F9BE028B5204B40E0BF1053F862F32CDEDFA7A63D469B994FDF8059257C3AFD14D9193A4264F2C8C502C1DC32932934C33DDD05DDCFA07BB9FD483B7B05F25E2412CBE617E15720091230A170D99F53B5FE42BF5BC6649C66F0C57AEA557F78C81B7C515B491BE6EC9F&h=3B9DFC9CB20AC32694CFE38572E8D2E3E4B9B62FA0192C555C023EF3B06F3443&directdownload=1&f=3340815&d=http://www.magicuneraser.com/.../Magic_Partition_Recovery.exe

Scan magic_partition_recovery.exe - Powered by Reason Core Security