universal mastercode.exe

darmiles

This is a setup program which is used to install the application. The file has been seen being downloaded from docs.google.com and multiple other hosts.
Publisher:
darmiles

Description:
universal calculator

Version:
1.0.0.0

MD5:
aa8d13b9372dcddc91ce8fd17ca2ee49

SHA-1:
0b459b0ebeeb504e56406cce03aaacf292924c66

SHA-256:
9e0e66dd9a411b0100bb88c4e65084540f560fe03571d76960c0c02af63ec31e

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/26/2024 2:25:03 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod86d.Trojan
1.3.0.4959

File size:
540.5 KB (553,472 bytes)

Product version:
4.0.0.0

Copyright:
darmiles soft

Trademarks:
darmiles soft

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\program\universal mastercode.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:YWmg3xsEg7sSpTVRBwXybp5AYag+RTlHtdvWx4pC9aSizqEQnlo1XHDaFOA:cg3qEgASjMybbtagw784J7QloFDa

Entry address:
0x6253C

Entry point:
55, 8B, EC, 83, C4, F0, B8, 4C, 23, 46, 00, E8, 44, 40, FA, FF, A1, F4, 42, 46, 00, 8B, 00, E8, 3C, 4B, FF, FF, 8B, 0D, D8, 43, 46, 00, A1, F4, 42, 46, 00, 8B, 00, 8B, 15, C8, F9, 45, 00, E8, 3C, 4B, FF, FF, A1, F4, 42, 46, 00, 8B, 00, E8, B0, 4B, FF, FF, E8, B3, 1B, FA, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
389.5 KB (398,848 bytes)

The file universal mastercode.exe has been seen being distributed by the following 38 URLs.

https://docs.google.com/uc?id=0B2qL83eH0LURRkVtMHlSb3JhNjA&export=download

http://fileshare1170.depositfiles.org/auth-1477358760757c72a80f2b9dd28541fe-187.148.88.175-20399110-155026568-guest/.../Universal_MasterCode.exe

http://dc408.4shared.com/download/.../universal_mastercode.exe

http://fileshare1170.depositfiles.org/auth-1474732843fc42384d6a05dd1e3ea8e8-181.110.4.91-2690605988-155026568-guest/.../Universal_MasterCode.exe

http://dc177.4shared.com/download/.../universal_mastercode.exe

https://mega.nz/temporary/.../zF8GHaqY

http://fileshare1170.depositfiles.org/auth-147551640793f8da2389e3f451796b91-148.101.225.184-1872132-155026568-guest/.../Universal_MasterCode.exe

http://fileshare1260.depositfiles.org/auth-1451529555d2d95b121eaf6ad9fef21d-181.31.181.109-2413855133-155026568-guest/.../Universal_MasterCode.exe

https://docs.google.com/uc?authuser=0&id=0B4tr0IBCq096dGJmaE1RUWRhd2M&export=download

http://fileshare1170.dfiles.eu/auth-1479907335c45e6b755c1747922f0f62-88.21.54.80-46392406-155026568-guest/.../Universal_MasterCode.exe

http://fileshare1170.depositfiles.org/auth-1475811226823738c4da8f4c966505d1-190.9.215.195-4805981-155026568-guest/.../Universal_MasterCode.exe

temp:Universal MasterCode.exe

http://fileshare1170.depositfiles.org/auth-1476301594d49c4826995b556e854dba-148.0.75.106-9847489-155026568-guest/.../Universal_MasterCode.exe

http://fileshare1170.depositfiles.org/auth-14793471184b4a5853c9ac7690304d68-177.237.168.9-40729502-155026568-guest/.../Universal_MasterCode.exe

http://fileshare1170.depositfiles.org/auth-14791835030c415d88c8a4bf3a9a1e3c-190.191.32.76-39176842-155026568-guest/.../Universal_MasterCode.exe

http://download43.mediafire.com/rowjqi23u2hg/.../Universal_MasterCode.exe

http://fileshare1170.depositfiles.org/auth-14698142599f9fc60c7d04116259ad74-190.110.224.101-2635060500-155026568-guest/.../Universal_MasterCode.exe

http://fileshare1170.depositfiles.org/auth-1469423083939fecc143bb57225d8ea0-189.132.33.67-2630797083-155026568-guest/.../Universal_MasterCode.exe

http://dc612.4shared.com/download/.../universal_mastercode.exe

temp:Universal_MasterCode.exe

Latest 30 of 38 download URLs

Scan universal mastercode.exe - Powered by Reason Core Security