net.fram work4 x86x64.exe

-=[By M.Baran]=-

This is a setup program which is used to install the application. The file has been seen being downloaded from share2.earthlinktele.com.
Publisher:
-=[By M.Baran]=-

Description:
~ Microsoft .NET Framework 4 ~

Version:
4.0.0.0

MD5:
48a138cf038e117b60a7bfa433a1d75f

SHA-1:
9639508115b61d3870c82f09f83624053ffd1d3c

SHA-256:
47fdd07b51dab64363c761420dcfd36dc595bf80d600f2918f4da52164e76d20

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/23/2024 2:30:48 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.PEPM.Gen
7.11.155.46

Qihoo 360 Security
Malware.QVM17.Gen
1.0.0.1015

File size:
48.7 MB (51,088,228 bytes)

Copyright:
Copyright © 2010 By M.Baran

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
9/14/2009 3:14:50 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1572864:Py47jKmGl68LsSwoDb6Iziu2nymxLyrc9z:a+Gl68FPjGu2DLyqz

Entry address:
0x1000

Entry point:
B8, CC, 4D, 42, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, A0, 07, EC, 41, A2, 94, 13, A3, C0, A4, 48, 77, DC, 6F, EC, D6, 3A, 62, 57, D6, BF, F2, 99, 15, 26, DA, F8, 1E, 91, B8, BA, AF, C7, 9B, A3, 00, DE, 8B, 25, DD, A2, 3A, 4E, 2F, C6, 94, A4, 03, E8, B7, 73, 83, 0B, 96, 43, 05, 20, 97, 11, 44, 94, 45, 51, 2D, 4A, 27, E2, 5A, 4E, 21, 86, 8F, A5, 3D, BA, 46, 90, 9D, 1E, A0, D7, CB, 07, DD, F9, D1, E3, 26, 1F, 73, 04, 77, 24...
 
[+]

Packer / compiler:
PECompact v2

Code size:
76.5 KB (78,336 bytes)

The file net.fram work4 x86x64.exe has been seen being distributed by the following URL.

Scan net.fram work4 x86x64.exe - Powered by Reason Core Security