winrar 5.01 x32.exe

The executable winrar 5.01 x32.exe has been detected as malware by 7 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download905.mediafire.com.
MD5:
0f4b1037dd9b56cfe02600c34edb8d70

SHA-1:
368764821ac9cdaaf6f8f49457c7af6f079cadb2

SHA-256:
51529b4be562c52736798da75942a49ad0335227bd7b89197a632afd6c956441

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
11/27/2024 1:54:26 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160708-3

AVG
Win32/Sality
2015.0.4604

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.E.gen
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.2223.0

VIPRE Antivirus
Threat.4721115
50706

File size:
1.8 MB (1,936,992 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\winrar 5.01 x32.exe

File PE Metadata
Compilation timestamp:
12/1/2013 9:08:34 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:kA3eIs8GtPzvzzRsxDd9GDfvMRwkLTbzONok:kA3jGtPzvRsxDjZT9k

Entry address:
0x1D158

Entry point:
F2, 22, EB, C7, C3, 8A, 92, B4, 3C, 86, C7, FF, C0, 4B, 1B, D6, 85, C5, 72, 02, 38, D1, 68, C9, BC, A2, 00, 85, EF, 88, E9, E8, 0E, 00, 00, 00, 8A, C3, FF, C0, 35, 4A, 32, BE, 63, 48, 0A, F1, 3B, DF, 2B, C9, 41, 0F, AF, F5, F7, C3, 7D, 7E, 69, 4F, F3, 2D, 04, E7, F2, 3C, 69, EB, 08, 42, 49, 77, 81, F9, E6, 02, 00, 00, 0F, 8C, DE, FF, FF, FF, 5E, 81, C0, F2, 33, 38, B3, 8B, E9, 22, D1, 88, D6, 73, 0A, 2D, 80, 02, 33, 2D, 86, FE, 0F, AF, DE, 85, CE, 69, C7, 3C, 11, E3, 07, C7, C0, B2, BC, 28, 92, 81, FA, FC...
 
[+]

Code size:
148 KB (151,552 bytes)

The file winrar 5.01 x32.exe has been seen being distributed by the following URL.

Remove winrar 5.01 x32.exe - Powered by Reason Core Security