sa-mp-0.3z-r1-install.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from files.littlewhiteys.co.uk.
MD5:
2f3104966265018a08d93a6f0eb45544

SHA-1:
a34f6240e71b3cddce275e1f4a29189a16aebe8f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 7:16:26 AM UTC  (today)

File size:
11.5 MB (12,068,671 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\Documents and Settings\{user}\My documents\downloads\sa-mp-0.3z-r1-install.exe

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:MYuZEB8OXjf0C2pPJoNRzB3/hPNrlmNs80+XoWNKRTfRGmvNStL1Q1jXXwr4+Cdh:MBGB5Tfslqfzd/tNoNHxNKRTfRGmvNSM

Entry address:
0x30CB

Entry point:
F6, C3, F1, 84, E4, 0A, EC, FE, CA, 89, ED, 70, 02, 87, ED, 81, E6, A0, 34, 59, 0F, 8D, 3D, 66, BF, D0, 45, 00, D8, FE, C9, E8, 7B, 00, 00, 00, 23, D3, 0B, D8, 88, F4, C7, C5, 6D, 7D, 05, 0C, 2B, C3, 04, 34, 86, E6, 14, 79, 84, DA, 80, F6, BC, 71, 03, 0F, B6, CD, 8D, 0D, 2E, D8, DA, FC, 8D, 15, 1A, 12, 55, AE, C6, C2, 45, 83, E0, 00, 81, C9, 50, 2D, CB, 62, F7, C2, 81, D4, 4B, F6, C6, C1, A6, 33, C2, 88, CD, 2B, CD, 29, EA, FF, CA, 1A, F6, 8B, D8, 0F, AF, CB, 0C, C6, 8D, 33, 69, C8, 1B, 8B, A2, 5E, B2, BE...
 
[+]

Entropy:
7.9998  (probably packed)

Code size:
22.5 KB (23,040 bytes)

The file sa-mp-0.3z-r1-install.exe has been seen being distributed by the following URL.

Scan sa-mp-0.3z-r1-install.exe - Powered by Reason Core Security