scrap mechanic - installshield wizard.exe

InstallShield

Product:
InstallShield

Version:
1.0.0.0

MD5:
b447ab3c3078d5b9d247c811dcb96bcd

SHA-1:
b4777fdbda2b9ccf7f8d977b04a1357236f0b59a

SHA-256:
578f65bd4c3e8751c55a66521c0be4c4d2d320653ac30ea250da3c728b157f31

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2025 10:34:26 PM UTC  (today)

File size:
10.8 MB (11,339,264 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
Scrap Mechanic - InstallShield Wizard.exe

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\scrap mechanic - installshield wizard.exe.part

File PE Metadata
Compilation timestamp:
7/12/2016 12:57:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
196608:oEAPle9sM3l0v1AuaFSD3mS80qwCtYh5wZjzEl4Ws8/XMe:oNPgiMNfFSD2OvCtYh58Kc

Entry address:
0xA8F69E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9602

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
10.6 MB (11,065,344 bytes)

The file scrap mechanic - installshield wizard.exe has been seen being distributed by the following 6 URLs.

https://dl.dropboxusercontent.com/content_link/.../file?dl=1

http://46.105.39.38/.../Scrap Mechanic - InstallShield Wizard.exe

https://dl.dropboxusercontent.com/content_link/.../file?dl=1

https://dl.dropboxusercontent.com/content_link/.../file?dl=1

https://dl.dropboxusercontent.com/content_link/.../file?dl=1

Scan scrap mechanic - installshield wizard.exe - Powered by Reason Core Security