sa-mp-0.3.7-install.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from dl.gta-sa-mp.de.
MD5:
2cd0b06960cf9372a9efb602aaa2958f

SHA-1:
fa2840dc3d64afce9fe6f43e5c9cc0dc0bcedf83

SHA-256:
7be093d87a319d5ff30972b97adf40871b72cb07a2d58bb05da46649ecd4725e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 4:41:48 PM UTC  (today)

File size:
15.6 MB (16,347,830 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\sa-mp-0.3.7-install.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:thRPtmflaNtY7G8t+LdFyBV9DVimtbA9yRbABehQtAuGuSwcBn:thRPtklUt3Nd2VvimtbeGbbhQtWBn

Entry address:
0x30CB

Entry point:
85, DF, 72, 08, 8D, 3D, 08, B3, 6F, 40, 89, FA, 30, F7, 22, C8, 0F, BE, C5, 87, D6, 84, C5, 0F, BF, FB, F7, C1, 35, 55, 4E, F5, 69, D9, 13, 92, 48, 5E, 21, F8, F7, C6, 9C, B6, AA, ED, E8, 00, 00, 00, 00, F3, FE, CD, 0F, AF, D7, 0F, BF, F0, 8A, D5, 8A, D4, FE, C3, 88, CF, BB, 93, C7, DB, C4, 2A, FA, F2, 57, 46, 5A, FE, C7, 1B, D8, 8B, CA, 69, F2, 39, FA, 4D, FE, 31, EF, F6, C0, 23, 81, C2, F3, BF, 62, 88, 33, ED, BB, 8E, CB, 17, EF, 0B, E9, 85, FA, 78, 0A, 86, DE, 69, FD, 5B, D9, 46, A3, 88, DB, 4F, 8D, 0D...
 
[+]

Code size:
22.5 KB (23,040 bytes)

The file sa-mp-0.3.7-install.exe has been seen being distributed by the following URL.

Scan sa-mp-0.3.7-install.exe - Powered by Reason Core Security