problem32.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.sudoktor.com.
MD5:
08aba04a2cd61a80f156f214da1b01eb

SHA-1:
2eb8a8964aefa862406601cae6b8e4319c9b726a

SHA-256:
e1ea0429beffdbd21fa5e253fb7688640c85ecdd6681afd0889ad2e827d13a94

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/27/2024 9:12:47 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.6979

Quick Heal
(Suspicious) - DNAScan
1.16.14.00

ViRobot
Worm.Win32.A.Net-Kolab.438272.J[h]
2014.3.20.0

File size:
428 KB (438,272 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\problem32.exe

File PE Metadata
Compilation timestamp:
7/23/2007 6:28:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:gNxSTuLOUT1rCxUKKlc0yYHdezOae/myym:g6u6M1rCx50c0yOJv/5

Entry address:
0x7698

Entry point:
E8, 19, 28, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 10, 75, 20, E8, A4, 15, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 35, 15, 00, 00, 83, C4, 14, 83, C8, FF, E9, 80, 00, 00, 00, 8B, 4D, 0C, 3B, CB, 56, 8B, 75, 08, 74, 21, 3B, F3, 75, 1D, E8, 75, 15, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 06, 15, 00, 00, 83, C4, 14, 83, C8, FF, EB, 53, B8, FF, FF, FF, 7F, 3B, C8, 89, 45, E4, 77, 03, 89, 4D, E4, 57, FF, 75, 18, 8D, 45, E0, FF, 75, 14, C7, 45, EC...
 
[+]

Code size:
56 KB (57,344 bytes)

The file problem32.exe has been seen being distributed by the following URL.

Scan problem32.exe - Powered by Reason Core Security