sa-mp-0.3x-r1-install.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from www.sa-mp.com.
MD5:
f0d8b880e600e3d44ca604b7cfe26469

SHA-1:
7df58354b1b2488535b908268408113b281db1b9

SHA-256:
835b1f8f5236430cc3ebc2c20a1678191c8ff2bfc0346f2ab270d6af4d83b5e2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:39:22 PM UTC  (today)

File size:
11.5 MB (12,082,906 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\sa-mp-0.3x-r1-install.exe

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:nrx2ZPT7bzIDdeO/Cu2g4hPNrlmNs80+XoWNKRTfRGmvNStLdmlwr4+CdZK:nr4ZP3bcDQoOtNoNHxNKRTfRGmvNSdEu

Entry address:
0x30CB

Entry point:
EB, 05, 0F, AF, E9, 8A, F9, 35, C0, 6D, 21, C7, 24, 31, 4D, 80, E0, 8E, 85, CF, 56, 0F, AF, DE, BB, 00, 00, 00, 00, F2, 8A, CD, 89, C5, BE, 45, A0, 29, 4E, 8D, 3D, 43, F8, FF, FF, FF, C6, FE, CE, F7, C7, 9E, 09, EA, D9, 86, C1, 03, DF, F2, 8B, C7, 81, C3, BE, 07, 00, 00, 87, C0, 88, FC, C7, C0, 83, B1, 22, FD, 0F, B7, FB, 89, C1, 81, FB, A3, 09, 00, 00, 0F, 82, BE, FF, FF, FF, 0F, AF, C8, EB, 0A, 0C, D7, 89, CD, 8D, 0D, DC, 92, B9, 6B, E8, 00, 00, 00, 00, 73, 0D, 8D, 0D, A1, 4C, FE, 00, B8, EE, 97, B9, 4D...
 
[+]

Entropy:
7.9998  (probably packed)

Code size:
22.5 KB (23,040 bytes)

The file sa-mp-0.3x-r1-install.exe has been seen being distributed by the following URL.

Scan sa-mp-0.3x-r1-install.exe - Powered by Reason Core Security