sa-mp-0.3x-rc1-install.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from www.sa-mp.com.
MD5:
d81ce55873b2fbf9be6159ea7cca16c4

SHA-1:
259a367901d1e06d232c26c31138c3ac52834320

SHA-256:
c6890504cf2f73205afdc9f32dc5cc39e85ebef515f8bebd45a79939ec7e3320

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 3:00:03 PM UTC  (today)

File size:
11.5 MB (12,013,584 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\sa-mp-0.3x-rc1-install.exe

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:62SGObzIDdeO/Cu2g4TA8AVXkxlY3gQ6yOrzDcHp4JR6B/4MRwr4+CdZz:6hGObcDQoOTA8wXkXAgQ/aop4zy/4MRn

Entry address:
0x30CB

Entry point:
3D, 5B, 9E, 00, 00, 71, 05, F6, C2, 5E, 87, DB, 0C, CB, 11, C7, 68, 7B, 0D, 81, 00, 0F, BE, DB, F2, 81, FD, FD, E5, E9, 33, 69, FD, C9, BA, D9, C6, 68, 7E, 25, 7A, 00, EB, 02, 23, EA, E8, 34, 00, 00, 00, 86, C8, 86, D2, 14, 54, F7, C6, 9D, E9, 56, 79, C6, C5, 40, 0F, BF, CB, BE, 43, D6, F5, 16, 2B, DB, 8B, ED, B8, 96, 6B, 78, D0, FE, CD, BB, 8F, 8E, 00, 00, 0F, BE, C6, B4, 5F, 28, CA, 81, C3, 82, 03, 00, 00, FE, CE, 22, C8, F3, B5, 66, 0F, B6, CD, 4A, 3B, DA, 5A, 8A, E5, 84, C7, 69, F1, 94, 04, 02, D0, 8D...
 
[+]

Entropy:
7.9998  (probably packed)

Code size:
22.5 KB (23,040 bytes)

The file sa-mp-0.3x-rc1-install.exe has been seen being distributed by the following URL.

Scan sa-mp-0.3x-rc1-install.exe - Powered by Reason Core Security