prepreinstaller_win.exe

The executable prepreinstaller_win.exe has been detected as malware by 10 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dw59o80yvpenp.cloudfront.net.
MD5:
881310ebb1a6624fe42f478bcf55bf3f

SHA-1:
8c1b706ef2bab9ecc5659827d51fab5e51d1d46d

SHA-256:
7dcb9b35607a0921aa8a6bb9083513ae362dd3cd75ff307b7d97911725eb45a3

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
11/25/2024 1:14:32 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160518-2

AVG
Win32/Sality
2015.0.4568

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Trojan.RDN/Generic Downloader.x
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.1015.0

Norman
Win32.Sality.3
28.05.2016 15:32:18

File size:
342.5 KB (350,720 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\prepreinstaller_win.exe

File PE Metadata
Compilation timestamp:
5/24/2016 9:47:02 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:GMb8+73bLcl/8KIsR9tyIflZ7oSk8fxOlLolXLKX/muoK7KLswo:GMbrH7WICl5OVolX4mjK7Rf

Entry address:
0xCB98

Entry point:
60, F2, F2, 87, D5, 69, F0, 6F, 6A, 98, C9, 18, CF, 02, CC, 81, E7, A8, 81, AC, 2F, 3B, D1, 0F, B7, D6, 13, FE, 0F, AF, D7, 81, EE, 85, 99, 00, 00, EB, 06, 81, F5, 51, 6F, A5, 6D, 81, EE, E9, 04, 00, 00, 69, C3, 25, 9C, D2, 9E, 69, C6, F4, E2, 45, 6A, 04, FA, 24, 48, 0F, B7, C7, 04, 6D, 0F, AF, C5, 0F, AF, C1, 0A, D6, 89, C1, E8, 00, 00, 00, 00, B8, 00, 00, 00, 00, EB, 02, 20, C3, 69, FA, 5F, 9C, B9, 9B, B9, 9C, 45, E1, B5, 86, D6, 05, 3A, 09, 00, 00, 75, 08, F7, C3, F3, D6, 9D, DF, B5, 81, 2D, 39, 09, 00...
 
[+]

Code size:
164 KB (167,936 bytes)

The file prepreinstaller_win.exe has been seen being distributed by the following URL.

Remove prepreinstaller_win.exe - Powered by Reason Core Security