sim card reader.exe

Pro Data Doctor Pvt. Ltd.

This is a setup and installation application. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
Pro Data Doctor Pvt. Ltd.

Description:
Data Doctor Recovery - SIM Card (Evaluation) 3.0.1.5 Install

Version:
3.0.1.5

MD5:
8c25ba78283df158186cd270dce510e0

SHA-1:
12f6d0cf727b61ddacc45b56fd19cb84caba4cdd

SHA-256:
04f6a269dd96c41e4ee14b2f7f30d3a1263dee68a6f0d0c7b03e1e2dfb48f13f

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/27/2024 6:24:43 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Trojan.Delf-2824
0.98/21411

File size:
512.6 KB (524,932 bytes)

Copyright:
Pro Data Doctor Pvt. Ltd.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\sim card reader.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:PtWNZ0mawE91JAnnP3Go7Qut5NZZYihps:P7wE91JAneoHT/ZZns

Entry address:
0x1609C

Entry point:
55, 8B, EC, 83, C4, F0, B8, F4, 5F, 41, 00, E8, 10, C8, FE, FF, B8, FC, 60, 41, 00, E8, 1E, 2C, FF, FF, 8B, 15, 54, 76, 41, 00, 89, 02, 8B, 15, 54, 76, 41, 00, 8B, 12, A1, 58, 76, 41, 00, E8, FC, D9, FF, FF, 8B, 15, 54, 76, 41, 00, 8B, 12, A1, 04, 76, 41, 00, E8, BA, 76, FF, FF, A1, 54, 76, 41, 00, E8, 2C, 1F, FF, FF, E8, 6B, B8, FE, FF, 00, 00, 00, FF, FF, FF, FF, 01, 00, 00, 00, 2A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8672

Developed / compiled with:
Microsoft Visual C++

Code size:
84.5 KB (86,528 bytes)

The file sim card reader.exe has been seen being distributed by the following 3 URLs.

https://dw.uptodown.com/dwn/KIKZI_gLDI3Ff3ezsjBdc-8Q5UTtsCGc0kuQxhukpSsL_o261fCo490GImfjxeCdClJxhGLTSXFxUuvbl0HeifrWV9vdHN8T8XMRdaTqJKlKpRUJYWQd8V7-1swgWoTk/GBXFuQnk12J3cX_hdd8IgsF-8IIMtc3CzFl48KHUZnh-yWKgZpbnEaNaaDo0FmtNxZDZjtR-JXWj9U4MWJtsAcbAiRTnn5PvIvgGLZFl1VECF8PZdCN0nku-ApSpYHmt/.../

Scan sim card reader.exe - Powered by Reason Core Security