nt_peshitta-es_peshitta_en_espanol_20110810.exe

The executable nt_peshitta-es_peshitta_en_espanol_20110810.exe has been detected as malware by 6 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download2190.mediafire.com.
MD5:
c9e824054b251d246772b488a7dd8c8d

SHA-1:
f7ae63c8f848f0799f590373b6f2aa58c90bde78

SHA-256:
d94256b3a3e537760f5c0d13117d9b59200b384fa5ce61970f16e9638e0f55b1

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
12/26/2024 7:35:59 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.223.1443.0

VIPRE Antivirus
Threat.4721115
50170

File size:
720.2 KB (737,457 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
9/16/2008 4:17:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
12288:uz5ODlo3ft0yHhpZsvYKWN1nAFDYdymIS8c3dSwRoTEWygKlg:uzIDloWchNN1mmIoNSwGTETc

Entry address:
0x1000

Entry point:
F2, F3, 69, D9, EC, C2, FB, 26, 69, C2, 2D, 0D, 60, FB, 8B, C2, 81, CA, ED, 46, 05, 65, 2A, EC, 85, D0, 46, 14, 7E, 3B, FB, F7, C6, F2, 0A, FB, 3F, 8D, 1D, 27, 72, 27, B4, 15, 1A, A6, D1, CF, 03, FE, 8D, 3D, BB, 71, 18, BD, 40, 69, F2, 76, 35, 59, DE, 8A, E9, E8, 21, 00, 00, 00, 80, D5, D0, 2C, 45, B1, 98, 81, F9, 2F, 5C, 9B, 64, C7, C3, F5, 27, 62, 59, C7, C6, E8, 5B, 23, 95, 69, D6, 8B, 11, 79, E2, 3B, E8, 5B, 48, BD, AA, BB, F3, 07, 48, 49, 81, C3, FC, A0, 03, 00, 35, 09, 7A, 41, 21, 24, 8E, 8A, E8, 81...
 
[+]

Code size:
80 KB (81,920 bytes)

The file nt_peshitta-es_peshitta_en_espanol_20110810.exe has been seen being distributed by the following URL.