spybot.exe

Ultra Setup Manager

HUSREN S. A.

This is a setup and installation application. The file has been seen being downloaded from offersrepo.com and multiple other hosts.
Publisher:
HUSREN S. A.  (signed and verified)

Product:
Ultra Setup Manager

Version:
3.4.26.719

MD5:
01a71176ae6513f245f3b8cd43186342

SHA-1:
4fbf5a1085d343bbc8a12ab3193ea8e323af1e77

SHA-256:
d38fcc13a3a1022b09fb59485279b3cdd78a7bfd7d73010df25cabb164d91133

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/26/2024 7:08:56 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.6379

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

File size:
123.3 KB (126,296 bytes)

Product version:
3.4.26.719

Copyright:
Copyright © 2015

Original file name:
i3KC.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\spybot.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/4/2014 2:00:00 AM

Valid to:
7/5/2015 1:59:59 AM

Subject:
CN=HUSREN S. A., O=HUSREN S. A., STREET=COLONIA 810 APTO: 502, L=MONTEVIDEO, S=MONTEVIDEO, PostalCode=11000, C=UY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
567CC889F234095C2B6877B8E8C3A484

File PE Metadata
Compilation timestamp:
4/28/2015 8:27:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:b17aJ7e+eD/JgV7vIgYqblWXAf+9vRGIQn2ncO:b1gV7vLYqblHdicO

Entry address:
0x19CDE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
95.5 KB (97,792 bytes)

The file spybot.exe has been seen being distributed by the following 50 URLs.

http://offersrepo.com/download.php?__tc=1430975885914&downloadName=adobe-flash-player.exe

http://offersrepo.com/downloads.php?signature=qualityscorei3&downloadName=tor-browser.exe

http://offersrepo.com/download.php?__tc=1431474485317&downloadName=whatsapp-for-pc-free.exe

http://offersrepo.com/download.php?__tc=1430940967838&downloadName=atube-catcher.exe

http://offersrepo.com/download.php?signature=qualityscorei3&downloadName=solsuite.exe

http://offersrepo.com/download.php?__tc=1430948564670&downloadName=atube-catcher.exe

http://offersrepo.com/downloads.php?signature=qualityscorei3&downloadName=cacaoweb-gratuit.exe

http://offersrepo.com/download.php?signature=qualityscorei3&downloadName=sony-vegas.exe

http://offersrepo.com/download.php?__tc=1431527372689&downloadName=google-earth-7.exe

http://offersrepo.com/downloads.php?signature=qualityscorei3&downloadName=whatsapp.exe

http://offersrepo.com/downloads.php?signature=qualityscorei3&downloadName=avast-2014-free.exe

http://offersrepo.com/download.php?signature=qualityscorei3&downloadName=teamspeak.exe

http://offersrepo.com/downloads.php?__tc=1431476342747&downloadName=adobe-acrobat-reader.exe

http://offersrepo.com/download.php?__tc=1432914132296&downloadName=atube-catcher.exe

http://offersrepo.com/download.php?signature=qualityscorei3&downloadName=bitdefender-total-security.exe

http://offersrepo.com/download.php?__tc=1430619189387&downloadName=atube-catcher.exe

http://offersrepo.com/download.php?__tc=1430859978214&downloadName=spybot-free.exe

http://offersrepo.com/download.php?signature=qualityscorei3&downloadName=counter-strike.exe

http://offersrepo.com/download.php?__tc=1430923804919&downloadName=atube-catcher.exe&downloadName=atube-catcher.exe

http://offersrepo.com/download.php?__tc=1431023586084&downloadName=adblock-plus.exe

http://offersrepo.com/download.php?__tc=1430666982761&downloadName=minecraft.exe&downloadName=minecraft.exe

http://offersrepo.com/download.php?__tc=1415269680420&downloadName=avast-2014-free.exe

http://offersrepo.com/download.php?__tc=1431202975249&downloadName=atube-catcher.exe

Latest 30 of 90 download URLs

Scan spybot.exe - Powered by Reason Core Security