winrar 5.20 -32x64 bit pl-full.exe

WinRAR

The executable winrar 5.20 -32x64 bit pl-full.exe, “WinRAR Setup ” has been detected as malware by 3 anti-virus scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from s6885.chomikuj.pl and multiple other hosts.
Product:
WinRAR

Description:
WinRAR Setup

MD5:
2e337e89f0bd811222556e4770d2953d

SHA-1:
0889eacda065da06e5c473f927e935c9ecd8ce9c

SHA-256:
d4574cf838277f885ebd1b700afa73749090d319961069f7dcd8fd24666f0be5

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
11/27/2024 5:31:59 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Detection.Undefined
7.0.302.0

NANO AntiVirus
Trojan.Win32.Gendal.dsussg
0.30.24.3079

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
43108

File size:
10.7 MB (11,212,025 bytes)

Product version:
5.20

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\winrar 5.20 -32x64 bit pl-full.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:igQ5dh5xeMzDQZ4yw0Er3f8ufJYUcowV06FmwqLsrvt4l:iHTxeZ4y2Df+B/mw5F4l

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file winrar 5.20 -32x64 bit pl-full.exe has been seen being distributed by the following 50 URLs.

http://s6885.chomikuj.pl/File.aspx?e=XPLQEjivFsHjr4R-885lohh9E2lBb17mZSa88xTsGmcpqzpOJDfeA6gFy_Dif1uXZ5QvBsFaqnWvRgKHrZPrRE95dnDjp2IArFUL-w-RGNrSxTMc0GsCfm4aq_Lsr0H4fbUIqB1KgWJ6eo8y8km0Nw&pv=2

https://doc-14-4o-docs.googleusercontent.com/docs/securesc/k0lv7jkc5drk53icjm7e21jg8j0nqvdj/sbs3c1r3thro3dkicnjg162sm86oh2tr/1479909600000/14401721873680297713/.../0B_jbXbFRSSnSYVZBckxGWGtqVGM?e=download

http://s6885.chomikuj.pl/File.aspx?e=XPLQEjivFsHjr4R-885loiSCj3_6orZ7sSpS69ZVmePTePV3J7LUpigiZWutzWSGiQBgcK6id_NMvKsOlGXjZJHZerVTky5SsztUmznpnjbEL9cjQuTUyPCXs8wkCtl17PW_ADXnWDFzFu1emgPV_oIjJ7FmmymKB9KHc7hCM1o&pv=2

http://s6885.chomikuj.pl/File.aspx?e=XPLQEjivFsHjr4R-885lojbJtfBQPIiBBX5vjl1fu1412nCKLCk3knJAoHwdcNZY0R0CdUQCZs2mVfM1leJCIX3xBrmks6WMRIO6BpYdxJdYcQ0QjhTBJSKk6fr4b3JlI1Z0nZ7e7zYBeZDB-yVS5Z3wmvEiZf4MdoKxT85PSZ4&pv=2

http://s6885.chomikuj.pl/File.aspx?e=XPLQEjivFsHjr4R-885lojbJtfBQPIiBBX5vjl1fu15S2gac0ZowCFEyo_8HwNHz5_8AkelNBMYpnSls8GjbfbFJhz5d5tma2oR7ZyHylhpXYrNNgnCzmXHWMEKEvzX3jvhnhLRxccBoPuaSWqPmBFNkQJH9jRsQUBGnuDhF2a4&pv=2

http://s6885.chomikuj.pl/File.aspx?e=XPLQEjivFsHjr4R-885loiSCj3_6orZ7sSpS69ZVmeMZG54et_jd3mV_HOCD32_JfE9rdV6ANwqC5FTWPhhSxf6c54KGW33S13oMaKqMObY7Gy7BLQaMXQLCgThxCFoqRz4zRKemN262no6nK9486nidKHtPi0vJXPLVn9ts260&pv=2

http://s6885.chomikuj.pl/File.aspx?e=XPLQEjivFsHjr4R-885loiSCj3_6orZ7sSpS69ZVmeO_9E54DLJAAohSxzpzC89OTNWEHcfKoOODXWC22oavwsFbgIDqBxfkh7G7E3HhTh1oAdHuyderw4pqQ38SQVZ7bnAjgXC5hZ2brxEHMHEjL3XAbXECknjU1uXHUoe-5yM&pv=2

http://dla.uloz.to/Ps;Hs;fid=67377099;cid=1954565111;rid=360074700;up=0;uip=188.120.212.57;tm=1466877146;ut=f;aff=ulozto.cz;did=ulozto-cz;He;ch=f9c47a0f5273a0a76bf364f4d3a59e76;Pe/.../winrar-5-20-32x64-bit-pl-full-exe?bD&c=1954565111&De

http://s6885.chomikuj.pl/File.aspx?e=XPLQEjivFsHjr4R-885lojbJtfBQPIiBBX5vjl1fu154oErnZQj-FJ2-9LbVSPYNliGiYcU42hk-3apftr77yu1lVKK2GXCdZhD85wTtJNjASFWC6zYClt1DccVO-v5i-k7n2Dxcn63nRQr9rFg3q5Au-_IUnlPX8h7aA-76sRM&pv=2

http://s6885.chomikuj.pl/File.aspx?e=XPLQEjivFsHjr4R-885loiSCj3_6orZ7sSpS69ZVmeNpZ9KXp014wxruCw-4t4pqaZowRGuVrWTGskOsN2RvANlb7ptfqCy_hjMBEMPGP7tAyj9xmUeREnZSQZzZzoauEqxi7LM9D6VWRCwI8BrrYcnnyNz08bBr_Pas_m2sMJyy3_4EOf1afkrP7h_MROrR&pv=2

http://s6885.chomikuj.pl/File.aspx?e=XPLQEjivFsHjr4R-885loiSCj3_6orZ7sSpS69ZVmeOvqTQDboW1oDtPLbzOee3fUoJq2-AMXv8jnlLWRtmWyhixovjlNYqFbNQkvS7ykkfFJmUtVjwcTlXM-aU6xmcEMVBzI7tsGSch6vRpqsXhEylIuopOeGtPHADozCvCIsk&pv=2

http://s6885.chomikuj.pl/File.aspx?e=XPLQEjivFsHjr4R-885lolARhii8TArgwIntcJTaLQ6M_jvYA_dthUxpDBz60lkgtQvlJplOMEQWgbjvOy4-yHo5N_4FjEl5KfgFR05CrToCHeMajaJDa4DmIcQZ-ysvT0AnAfxpoS1zWBMMHlUqZSBG9j2hQat073wrn5pRy0M&pv=2

Latest 30 of 60 download URLs

Remove winrar 5.20 -32x64 bit pl-full.exe - Powered by Reason Core Security