monstertruckfurysetup.exe

This is a setup and installation application. The file has been seen being downloaded from s10153.chomikuj.pl and multiple other hosts.
MD5:
07d249c1fc138631c766ea4618a9159d

SHA-1:
32e285d6f66aa6c069c4c6635b2f0202333aa55b

SHA-256:
32df562156d3d8a9e14c2c25a1dbb6a152f38c3fda5a9895794278046284b21c

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/25/2024 3:25:59 PM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Trojan-Dropper.Win32.Delf
t3scan.2.0.3.0

VIPRE Antivirus
Trojan.Win32.Generic
19036

File size:
44.6 MB (46,814,305 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\monstertruckfurysetup.exe

File PE Metadata
Compilation timestamp:
2/7/2004 9:26:11 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:D4Yul3b8G0JMuwETbxMw0cEx7b7ebbdJvprGRzpxdDhffbMfL4APgwN7dwL+Koyd:D4YSb8zvwEx0cs7YblGR/z24/Y7dwF/d

Entry address:
0x3F88

Entry point:
83, EC, 0C, 53, 55, 56, 57, C7, 44, 24, 10, 70, 92, 40, 00, 33, DB, C6, 44, 24, 14, 20, FF, 15, 2C, 70, 40, 00, 53, FF, 15, 84, 72, 40, 00, BE, 00, 54, 43, 00, BF, 00, 04, 00, 00, 56, 57, A3, A8, EC, 42, 00, FF, 15, C4, 70, 40, 00, E8, 8D, FF, FF, FF, 8B, 2D, 90, 70, 40, 00, 85, C0, 75, 21, 68, FB, 03, 00, 00, 56, FF, 15, 5C, 71, 40, 00, 68, 68, 92, 40, 00, 56, FF, D5, E8, 6A, FF, FF, FF, 85, C0, 0F, 84, 57, 01, 00, 00, BE, 20, E4, 42, 00, 56, FF, 15, 68, 70, 40, 00, 68, 5C, 92, 40, 00, 56, E8, 9C, 28, 00...
 
[+]

Entropy:
7.9973  (probably packed)

Code size:
23 KB (23,552 bytes)

The file monstertruckfurysetup.exe has been seen being distributed by the following 7 URLs.

http://s10153.chomikuj.pl/File.aspx?e=iBKvTLQlvITJEfiLIzalj9A3Gf7DS5r_PpNar5g7COE20A43J0iMojS1UXTKRrjtqRidQmHDwMUo7N__xuCrLDZDX5rM66JAi3E6ygx3Ojueb4hmMzMh7t95Bo7WDT8SmPvLodIWCbGnEePZjVFrCeHJwUVwCyDWHGSkexMrvmw&pv=2

http://gsf-cf.softonic.com/32e/285/.../file?SD_used=0&channel=WEB&fdh=no&id_file=48600&instance=softonic_en&type=PROGRAM&Expires=1476657723&Signature=SRY~kjGGA~JiMpc4cJb72Y9pQL4fX0gb4S9pQzmczUw28slhcr39KK9gKAcPd9iLExD6-RnqipNlZ-UNXV7vFp3c71tZzSzCuUmuuSHlLBZ5cHJ0LNr~RvSyQFX50Csy3aE0qAVzxpZPtC0xn4ZmDSG64RSXOSmL9fdR-4hJPKY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=monstertruckfurysetup.exe

http://s10187.chomikuj.pl/File.aspx?e=iBKvTLQlvITJEfiLIzalj9MNQQBaykDWBctbnyFMHgIwnq7nhdFoyM-YhOXWIsgW5PeGumNKtwduDP5R7s4IPJF8do0LG-6Skh7WisL3P_iuyuA0rZqePqf7Ps6tXJm3rZX3z4-GtC7x0g7c1XL5C1TTA2UNRKY1jzlsdHSdjyg&pv=2

Scan monstertruckfurysetup.exe - Powered by Reason Core Security