sa-mp-0.3.7-install.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from dl.gta-sa-mp.de.
MD5:
2fe6280b4dc9340517153ee1d8ce9925

SHA-1:
66a8949d703a5a21aafe08976b013471ebce9dd9

SHA-256:
e542135a3dd3dfc06597b2878974a4ee429feb2d2e6e3407b7fcc177e92a11f0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:51:15 PM UTC  (today)

File size:
15.6 MB (16,347,830 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\sa-mp-0.3.7-install.exe

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:ChRPtmflaNtY7G8t+LdFyBV9DVimtbA9yRbABehQtAuGuSwcBn:ChRPtklUt3Nd2VvimtbeGbbhQtWBn

Entry address:
0x30CB

Entry point:
FE, CD, 0F, BF, DB, 69, F0, A4, 63, F5, AA, F2, 0C, 5F, 05, 8F, B8, 84, 61, 1B, F9, FE, C7, 43, 20, E4, 75, 08, 89, DF, 8D, 1D, 1A, FA, DC, 6B, 85, D7, 71, 05, 87, D8, F6, C1, 0F, 8D, 37, 85, EF, 73, 03, 0F, B6, D9, 0F, AF, CB, 56, B7, 81, 3D, 9E, 28, 2E, B9, 5A, 81, FF, 84, BA, 37, E5, 2A, EA, 41, 12, E9, 2B, EA, 24, FC, BF, 00, 1D, E6, C7, 87, D0, 32, CA, 87, EE, BD, 00, 00, 00, 00, 05, 7C, 6C, BD, 10, 80, CC, B0, 89, D3, 0F, BF, F5, 86, CD, C7, C2, 66, 2A, 40, 28, F6, C5, E1, 81, C5, 4D, 06, 00, 00, 8A...
 
[+]

Entropy:
7.9999  (probably packed)

Code size:
22.5 KB (23,040 bytes)

The file sa-mp-0.3.7-install.exe has been seen being distributed by the following URL.

Scan sa-mp-0.3.7-install.exe - Powered by Reason Core Security