virtualbox-4.3.6-91406-win.exe

Oracle VM VirtualBox

Oracle Corporation

This is a setup program which is used to install the application. The file has been seen being downloaded from www.filehorse.com and multiple other hosts.
Publisher:
Oracle Corporation  (signed and verified)

Product:
Oracle VM VirtualBox

Description:
VirtualBox

Version:
4.3.6.91406

MD5:
464138f963d0284aa0a223c683ffd0bb

SHA-1:
d7c5e8a391b5f8e4d10b0707b93120d2b84769eb

SHA-256:
b5c2d57d453496e057eaf689e03a65e5cf607caa6ec09f2f4823d9d70a43b366

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/7/2025 6:28:32 PM UTC  (today)

File size:
101.4 MB (106,322,704 bytes)

Product version:
4.3.6.r91406

Copyright:
Copyright (C) 2009-2013 Oracle Corporation

Original file name:
VirtualBox.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\virtualbox 4.3.6 build 91406 final.mazika2day.com\virtualbox-4.3.6-91406-win.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/8/2011 2:00:00 AM

Valid to:
2/8/2014 1:59:59 AM

Subject:
CN=Oracle Corporation, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Oracle Corporation, L=Redwood Shores, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
519BD967F908015521A20C0E9316F489

File PE Metadata
Compilation timestamp:
12/18/2013 6:37:07 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3145728:1cKAvk99sZQRy10U5OphXK7dWNVrup5fGZRpCfUW:1clkZRU6XSWNFupMCfUW

Entry address:
0x2FB7

Entry point:
E8, 01, 26, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 38, A8, 4F, 00, 89, 0D, 34, A8, 4F, 00, 89, 15, 30, A8, 4F, 00, 89, 1D, 2C, A8, 4F, 00, 89, 35, 28, A8, 4F, 00, 89, 3D, 24, A8, 4F, 00, 66, 8C, 15, 50, A8, 4F, 00, 66, 8C, 0D, 44, A8, 4F, 00, 66, 8C, 1D, 20, A8, 4F, 00, 66, 8C, 05, 1C, A8, 4F, 00, 66, 8C, 25, 18, A8, 4F, 00, 66, 8C, 2D, 14, A8, 4F, 00, 9C, 8F, 05, 48, A8, 4F, 00, 8B, 45, 00, A3, 3C, A8, 4F, 00, 8B, 45, 04, A3, 40, A8, 4F, 00, 8D, 45, 08, A3, 4C, A8, 4F...
 
[+]

Entropy:
7.9887  (probably packed)

Code size:
250 KB (256,000 bytes)

The file virtualbox-4.3.6-91406-win.exe has been discovered within the following program.

Publisher's description - “Join an epic adventure with the Angry Birds in the legendary Star WarsTM universe! Use the Force, wield your Lightsaber, and blast away Pigtroopers on an intergalactic journey from the deserts of Tatooine to the depths of the Pig Star -- where you’ll face off against the terrifying Darth Vader, Dark Lord of the Pigs! Rebel birds, striking from a hidden base, have won their first victory against the evil Imperial Pigs.”
www.rovio.com
7% remove it
 
Powered by Should I Remove It?

The file virtualbox-4.3.6-91406-win.exe has been seen being distributed by the following 27 URLs.

http://www.filehorse.com/download/file/.../

http://download1898.mediafire.com/a41lski0kxgg/.../VirtualBox-4.3.6-91406-Win.exe

http://gsf-cf.softonic.com/d7c/5e8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=58734&instance=softonic_es&type=PROGRAM&Expires=1422014847&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=d3v7hfPp-RR7WBJpC0LUfMz1oYRJI4IzjHgCxe2aFJQSWYkU~0vAGJx4dp-FdjPkEG3JGKmfN4DrOKDOb2aOT-lpxtYnSOeVu0MNNUEsLIWVykfQ--cpPPye4H3lNVj32bjJoYPR2TCEmMtysH1KQViB~LwRxPuDtMeb1cScYcw_&filename=VirtualBox-4-3-6-91406-Win.exe

http://gsf-cf.softonic.com/d7c/5e8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=58734&instance=softonic_es&type=PROGRAM&Expires=1425963608&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=evgCAQ2qzptqpmpqapZ2Pcx3G0qJ3Y0t9vxoXBgysfFygf0CAE3r2TUkXZNJDS~Z~usw26~0R1hhjD1Zr61QMjjgp4DvFAwPyQpW-C9DPZq87TiINH-mznwM-m7ECRj0PZmBalnacxQXXLOl7pyUOcoTldNRgkgaP5a0OBxlhKY_&filename=VirtualBox-4-3-6-91406-Win.exe

https://doc-0k-08-docs.googleusercontent.com/docs/securesc/ohjpen1qct3rj5j6i1us6gro6p4r7il9/lqos52cgth6nlcred5uhckbqsma57fo5/1471888800000/14233617193875206893/.../0BwCijh0TRpHvTDRQT181elc2Mjg?e=download