mandriva linux spring one 2008.1 rc2 mandriva linux spring free 2008.1 rc2.zip.exe

Artur Arakelyan

The executable mandriva linux spring one 2008.1 rc2 mandriva linux spring free 2008.1 rc2.zip.exe has been detected as malware by 1 anti-virus scanner. The program is a setup application that uses the Nullsoft Install System installer.
Publisher:
Artur Arakelyan  (signed and verified)

MD5:
d442194a5414f37cb50f86048d6c918c

SHA-1:
5f0679e3e14685630d7b5a5deb24f47e449c6115

SHA-256:
ce9a36b3a762bb47132cf68cf2c73f975eecf9823e7ac3ea230b37d9e5da0da8

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/15/2024 5:32:33 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.21.17

File size:
222.2 KB (227,544 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\downloads\mandriva linux spring one 2008.1 rc2 mandriva linux spring free 2008.1 rc2.zip.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
4/25/2016 3:01:09 PM

Valid to:
4/25/2018 3:01:09 PM

Subject:
CN=Artur Arakelyan, O=Artur Arakelyan, L=Almaty, S=Almaty, C=KZ

Issuer:
CN=StartCom Class 2 Object CA, OU=StartCom Certification Authority, O=StartCom Ltd., C=IL

Serial number:
6067608CB66F8244DFF5FAA6BF8E54ED

File PE Metadata
Compilation timestamp:
1/5/2012 9:21:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

Entry address:
0x4109

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 30, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8B, 3B, 00, 00, A3, 8C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A9, B2, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, AA, B2, 40, 00, C7...
 
[+]

Code size:
34 KB (34,816 bytes)