na_maloom_afraad_full.exe

The application na_maloom_afraad_full.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from ttvdownloads.maynemyltf.netdna-cdn.com.
MD5:
c2671b0d1f0b79d50dee50f6ca20a375

SHA-1:
4ea29b51eff5ab237ba883a3de1b29d1bbbbda5e

SHA-256:
9fab4d6d44982162567705323ebdbd69a14dff0a9e39d5b9c0fa98f34a79ba68

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/25/2024 1:08:30 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Rootkit-gen [Rtk]
160327-1

Emsisoft Anti-Malware
Application.Bundler.LT
11.5.0.6191

ESET NOD32
multiple threats
8.0.319.0

McAfee
Program.Artemis!E50423C905E2
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.217.477.0

Norman
Application.Bundler.LT
29.03.2016 06:29:16

File size:
181.4 KB (185,704 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\na_maloom_afraad_full.exe

File PE Metadata
Compilation timestamp:
12/6/2009 3:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:0Lk395hYXJqbYQYN/MK4NWMtCn3eNwPU/A9pOl+fZelylaIEP9pEHPX2UHMDkLAU:0Qq0NrS3L8YhZmyltEP9iGUqghQlaX

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.7127

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file na_maloom_afraad_full.exe has been seen being distributed by the following URL.

Remove na_maloom_afraad_full.exe - Powered by Reason Core Security