napiprojektbuild_2.2.0.2399.exe

NapiProjekt

This is a self-extracting archive and installer. The file has been seen being downloaded from www.bytesendclear.com and multiple other hosts.
Product:
NapiProjekt

Description:
NapiProjekt Setup

Version:
2.2.0.2399

MD5:
7493c35432158f9d030f62647e284b6f

SHA-1:
7bd36860b0fe4f95cfb567a85844881f7c734b29

SHA-256:
d1baa923cf2a8ed8c93393b74df3a29907da85ccb2eb82795d431f6493f87fca

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/23/2024 6:22:28 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clodbb5.Trojan
1.3.0.4924

ESET NOD32
8.9455

K7 AntiVirus
Riskware
13.176.11239

Trend Micro House Call
TROJ_GEN.F47V0930
7.2.53

File size:
9.5 MB (9,989,013 bytes)

Product version:
2.2.0.2399

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\napiprojektbuild_2.2.0.2399.exe

File PE Metadata
Compilation timestamp:
10/9/2012 10:48:22 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:QKKgZ8F9NpGbZvjsrmctVI8UsXKCptI0ZLmNoYeXD:NKgZ8F9NpGtLsrmcLIBQu8LmNcT

Entry address:
0xF3BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 64, ED, 40, 00, E8, E8, 71, FF, FF, 33, C0, 55, 68, 89, FA, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 45, FA, 40, 00, 64, FF, 32, 64, 89, 22, A1, 48, 3B, 41, 00, E8, BE, F7, FF, FF, E8, 65, F3, FF, FF, 8D, 55, EC, 33, C0, E8, F7, C3, FF, FF, 8B, 55, EC, B8, 4C, 66, 41, 00, E8, 6A, 58, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 4C, 66, 41, 00, B2, 01...
 
[+]

Code size:
59 KB (60,416 bytes)

The file napiprojektbuild_2.2.0.2399.exe has been seen being distributed by the following 26 URLs.

http://www.bytesendclear.com/0rVHN_5LnRcUkKOeYM0nGr2dpZU8pPO9gxJ1A9W1gNfJYqsNmgEn5oGsMbrA3K0D22KqJmKOHKgLVq68lCE CsJC49e2kKieGQJSOGo6cJ_jl9MOrzWlWfvUtT7AeSXocN8sZYgszmA0ZdUSEbPy66T5gDfJD3CWzTbpon4vxKPl1MpJ7M5h C8QlLlqpcoQWzxwEdQVUWJe5x9AU_FoBTK EyYyKXABN1qLmmkhND3yOJZZon_3imNZhFhKbEtzoaGqKk8_V1mOe7JAZ8B1FD1gh_oPph0MhVMu8gSusPIsV_IdnEr9JLaYtX93QyrM0AGe_gptU5hR1_iX7B8krY9OjSTZB9uBiVpJPoOUK5RCf5X8Pmn6M5EOhj5f1bUHut4wVvWBpuj3g bfXcKSzySDVqC6bu fJ7EH9ojmuZjQKB2YJWxii2sEO12XLuH_SCBrV8YypLbCPPwUbDIw jmHpgUIyjA6l9FusgY2_0QhVRvuejIOPhCR0ouPMqDEVeFuB06t147lzDjnI3r10ytK_JJ9PE7mdlIk 2JTmWaIYryxG6P67KJzNGkgHfKgjaUiy6 45gpbAcKRa9GmP4hhrSNoig==-G10AAEQ39bxqn7tH _YWlCKORbqNzYFDDhzaNQkstAA08JBtT0I0io41ViMXuxcFNstpLlg7KY7anz d2zRR1MFhVwpyBS9cQxu_VdJPAQ==

http://s6271.chomikuj.pl/File.aspx?e=aOtrLSyptlD9NpakmNWueSyXWQVdUw2MyCpTx0r2yAxKu3Qwo9rlvH3sdM2bzm5U3zgYldfJUnSxWnRfHpE_KcMqapGuAFS1jT54YJGHU6KW3MuzVMILsq6tYlNqdzYT0N13AQ5aoreq_M73JrtkvSzgPUq5cNbYwjFJtVHc1yI&pv=2

http://www.bytesendclear.com/0ZX6grs EiLN8tCuaTEmVvahVEkqi1v7fglGm8NL7TmKdWG6ha 8Do4AQqJn20uPbeIyWwi 5pQklnwdhbT5gZ9nXxHaeF7YRhzbzVRWY5ulnlTKVybW01hUKyVUH7ic0oal2yAMLK n0Oeqe5TF090yl8vMhJnBoOpMTderBscYhjcHsLr8 3qjjigo5GqykZI4o7mvHSM8eyn yuhFwNeRSyTEzvDJ7HkhR8qjLCLM5q2D6E33Q32qZpsSGCK3_UtNLQkSLET zr4ngZq99Jteo727h PZeDY_Tjr7HbBF0ji5jMVWvJqrexPIxJlruFE96eMgccqlQ0AQI1NEsI1CGlCDk1QfCNB39OUAz7XMUUvJBGtsZm7BorD_lO5 jL4cyVkcBdVqDLRdnjXGncOVLzbCWqH72LnxTXhDkQES9NAPoFE2bG9Ki6mHwaoraz93DtjBUpqyhJN6aMmsY4axnKwnctvPBlDu9WZeu81h1gvUHaxl9NFXFxExO13ia qU1W2pssH H8SNz ukCQgsN2I0el1U5lRJ0QBkF163fmN5km7T85_htrS0D4we4PtERYoPtdhURSllsRZzgj1leSExaVi0UGOOimG1qrAPNDwgKcM=-G10AAEQ39bxqn7tH _YWlCKORbqNzYFDDhzaNQkstAA08JBtT0I0io41ViMXuxcFNstpLlg7KY7anz d2zRR1MFhVwpyBS9cQxu_VdJPAQ==-E

http://s6271.chomikuj.pl/File.aspx?e=aOtrLSyptlD9NpakmNWueSyXWQVdUw2MyCpTx0r2yAyr1wqI8PDgzeK_AKlmX_KqJ7eQGPoRVfUl7140LAKwSifTUow1LSCgI_LaWUSyzjkrC-SqCozJuu8jVdLRQrK80S8_IdIMFYXqi6i8Ams5O_Xzh-w9rUkIbGFr3E-p2sI&pv=2

http://s6271.chomikuj.pl/File.aspx?e=aOtrLSyptlD9NpakmNWueSyXWQVdUw2MyCpTx0r2yAyJ8SSzDNi-jt15vxPl39OTJ3i7Jl5WvRcs4ve_Khk_6Uc-f0xR5c1mkP3J8vFf_kpToWkBc9odnh6RhXIF-j4zW906-cKNDP1_HSnF6ntpu7O_loakhJPK9ihADS3LoKI&pv=2

Scan napiprojektbuild_2.2.0.2399.exe - Powered by Reason Core Security