unitydownloadassistant-5.4.0b20.exe

The executable unitydownloadassistant-5.4.0b20.exe has been detected as malware by 8 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from beta.unity3d.com.
MD5:
af5ce92b54f03d4b7d1fae640df883a5

SHA-1:
888e13e392be50a590cc0202ae28f11aa6a43ac7

SHA-256:
eb80070ded3656a7d78ab7297b484b81192f49db2c10e6816073a9f205b8c956

Scanner detections:
8 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
1/12/2025 4:25:21 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160518-2

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Virut.AI!Generic
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.2897.0

Norman
Win32.Sality.3
28.05.2016 15:32:18

VIPRE Antivirus
Threat.4721115
50318

File size:
741.1 KB (758,904 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\unitydownloadassistant-5.4.0b20.exe

File PE Metadata
Compilation timestamp:
1/5/2016 4:04:40 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:M+6GM1LLiQ9FHZkPdXKDMeK33nG5OfBRtCi7sRftMgBUSfIU5BRdm2rqbznm:M3GuLiQlkPwO4tRdmkwnm

Entry address:
0x38BE

Entry point:
60, 0F, B6, CA, 87, CF, 0F, BF, C2, 89, D0, 84, C5, B1, A4, 8A, F5, 8B, DD, 68, 8E, 1C, 25, 00, 2D, 14, 94, 0A, D3, 83, E0, 00, BD, 0A, 97, CA, B3, 84, FF, C6, C1, 71, 0F, AF, CE, 31, C1, F6, C3, 6A, F2, 89, CF, 0F, B6, FA, B1, 59, 49, 69, FE, 72, D3, 27, 45, 49, 8D, 15, 45, FF, FF, FF, 69, E8, F9, A8, 78, 1D, 86, CD, 84, EB, 81, F2, 47, 04, 00, 00, 10, E1, 10, E1, 52, C7, C1, 08, 55, 4F, 39, 5B, 85, FF, FF, C6, 81, F3, 03, 04, 00, 00, 89, F1, 03, C3, 80, DA, 2B, B6, 5F, 05, 00, 01, 00, 00, 01, CB, 0F, B6...
 
[+]

Entropy:
4.9864

Code size:
28.5 KB (29,184 bytes)

The file unitydownloadassistant-5.4.0b20.exe has been seen being distributed by the following URL.

Remove unitydownloadassistant-5.4.0b20.exe - Powered by Reason Core Security