sambc-fb.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from sam-broadcaster.soft32.com.
MD5:
deaf20239527661e22bf6fdec9b54a52

SHA-1:
6d5d18c8f9fd6b36680cb61aaba93dfcf4fd3ed8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 9:40:31 AM UTC  (today)

File size:
25.9 MB (27,177,272 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\Documents and Settings\{user}\My documents\downloads\sambc-fb.exe

File PE Metadata
Compilation timestamp:
12/6/2009 4:20:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:SWMGKNmeNnJGY3xCqPah66RRk4kDGaFykMN0xKDqT6WYYCCU8LLZB/1lFE96TdXH:S9JtJahJRxqG3kMygu6sbH9aOL4i

Entry address:
0x30FA

Entry point:
60, 8B, C6, 84, D9, 47, 0F, BF, FD, 2A, E1, 69, C2, 68, 9D, 37, A9, 34, 7C, 38, E3, 0F, BE, FA, 89, C5, 81, F0, 72, B5, DD, 04, 68, 21, 7D, 4C, 00, 68, 9B, C5, 7F, 00, 84, FC, E8, 3E, 00, 00, 00, 31, DE, 87, DD, 8B, EE, 0F, BE, C9, 19, D3, 8D, 35, 51, 9C, 4A, 2D, EB, 08, F6, C1, 23, 8A, FE, C6, C5, E9, 55, 8D, 1D, 0E, 98, 37, 10, 85, F5, 5A, 0F, BF, DE, 87, D9, 85, CE, 4E, 0F, B6, FB, 33, C2, 72, 0A, 89, C9, 0F, AF, F2, BF, 88, 70, A3, 85, 11, F7, 25, 83, 45, 2E, 0F, 0F, B6, D9, 86, CC, EB, 08, 69, D2, D3...
 
[+]

Entropy:
7.9955  (probably packed)

Code size:
23.5 KB (24,064 bytes)

The file sambc-fb.exe has been seen being distributed by the following URL.

Scan sambc-fb.exe - Powered by Reason Core Security