unsigned.exe

CI_utility

CI Utility

The executable unsigned.exe has been detected as malware by 1 anti-virus scanner. The file has been seen being downloaded from www.findmysoft.com.
Publisher:
CI Utility

Product:
CI_utility

Version:
2.2.19.44

MD5:
b8b3e2cd8f04872237b73ce925e00052

SHA-1:
70fdbae3e46f65e675979ec5604862685645189f

SHA-256:
361d2f7f9112b9fd1c69ec400136b9e6868ad944ccf2a5c453325bfa9414cd01

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/17/2024 11:48:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
15.7.23.23

File size:
681.5 KB (697,856 bytes)

Product version:
2.5.00.01

Copyright:
(c)2014-2015

Original file name:
CI_utility

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
6/16/2015 12:15:10 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:+HAN0Fqy2DIj2vroe1Hw7d2s+6PjD8aP7fJlNgeCK7JTvHCO+STNGivJnxE7w/+a:5N0oy4Ij4rgP+6flNQ+TvCOdTNGivJnv

Entry address:
0x5981B

Entry point:
E8, 5B, 7E, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 8B, FF, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, 89, 98, 45, 00, 6A, 00, FF, 75, 0C, FF, 75, F8, FF, 75, 08, E8, E7, 01, 01, 00, 8B, 45, 0C, 8B, 40, 04, 83, E0, FD, 8B, 4D, 0C, 89, 41, 04, 64, 8B, 3D...
 
[+]

Entropy:
6.6380

Code size:
447.5 KB (458,240 bytes)

The file unsigned.exe has been seen being distributed by the following URL.

Remove unsigned.exe - Powered by Reason Core Security