ultraviewer_setup_5.0_en.exe

UltraViewer

DucFabulous

The executable ultraviewer_setup_5.0_en.exe, “UltraViewer Setup ” has been detected as malware by 10 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from dl2.ultraviewer.net.
Publisher:
DucFabulous

Product:
UltraViewer

Description:
UltraViewer Setup

MD5:
fab7505d0909cfd2f3c533c0a9b42eaa

SHA-1:
522a74543c9f8265c17af5626978b2b19b462c73

SHA-256:
86ec84dd109118f87230771e981d665c058ffe3cd4637aa4e7f95b51f487e15d

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
12/27/2024 9:29:40 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160326-0

AVG
Win32/Sality
2015.0.4355

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.217.1958.0

Norman
Win32.Sality.3
02.04.2016 17:35:19

VIPRE Antivirus
Threat.4758034
47854

File size:
1.9 MB (2,035,495 bytes)

Product version:
5.0.0.25

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\ultraviewer_setup_5.0_en.exe

File PE Metadata
Compilation timestamp:
10/13/2013 3:19:32 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:ZbhcnVj6iVVUrR10504lqlUf4n4qsSmxs+g:JuldQR1o1lN6doxDg

Entry address:
0x113BC

Entry point:
85, DE, 48, F7, C7, CE, 2D, 93, 38, 13, FF, 87, E8, 0F, BF, EA, BB, 7A, 7B, 00, 00, 00, EE, 81, F3, 7F, E4, 00, 00, 76, 02, 0F, CA, 81, EB, C3, 0A, 00, 00, 2B, CB, 86, DC, 51, 75, 03, C6, C7, 48, 56, 68, 03, 73, A4, 00, BA, 01, 75, 5C, F2, E8, 00, 00, 00, 00, 81, FD, 17, 84, 00, 00, 71, 02, 8A, CC, 35, E2, DD, 64, 72, 74, 03, C6, C0, 48, 81, FB, 03, 97, 00, 00, 5A, 35, DB, C1, CD, E9, 69, DB, 96, E2, 64, 69, 88, E0, 0F, C9, F7, DD, 85, CB, 8B, FA, 68, 43, 0F, 00, 00, 09, F5, 5D, 81, ED, 43, 0F, 00, 00, 87...
 
[+]

Entropy:
7.9687  (probably packed)

Code size:
63.5 KB (65,024 bytes)

The file ultraviewer_setup_5.0_en.exe has been seen being distributed by the following URL.

Remove ultraviewer_setup_5.0_en.exe - Powered by Reason Core Security