spirit.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from download1226.mediafire.com and multiple other hosts.
MD5:
2b13ffc376f749f74a105a441f4a1517

SHA-1:
a9c662ecad67fad7712b0873a95db7c830410617

SHA-256:
c8561e9b17c476344caadcfef70ce47d92c6c000261c549757457f4bfb190b7d

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/27/2024 5:14:57 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsPikanver
1.3.0.4959

Sophos
Spirit Jailbreak
4.98

File size:
4.4 MB (4,570,608 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\spirit.exe

File PE Metadata
Compilation timestamp:
5/3/2010 9:16:34 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
98304:VbQaK1Ed6rB2Ulpi9L+1xyncX0yVXOM81tYzuUx1pL3FBJf4pip5q:R+1/rBXTiXncXtVeM8jYCUbV3KpipE

Entry address:
0x197940

Entry point:
60, BE, 15, 30, 52, 00, 8D, BE, EB, DF, ED, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.9421

Packer / compiler:
UPX 2.90LZMA]

Code size:
468 KB (479,232 bytes)

The file spirit.exe has been discovered within the following programs.

Apple Application Support  by Apple Inc.
Apple Application Support is required to run iTunes, QuickTime and other Apple installed products (do not remove this if you use any of these programs). If you remove this program you will need to reinstall it in order for iTunes to load.
www.apple.com
6% remove it
www.apple.com/fr
9% remove it
8% remove it
 
Powered by Should I Remove It?

The file spirit.exe has been seen being distributed by the following 10 URLs.

http://download1226.mediafire.com/jbgys477n9jg/.../Spirit.exe

http://download1118.mediafire.com/9zp5dd5ef85g/.../Spirit.exe

Scan spirit.exe - Powered by Reason Core Security