winrar-x64-50b2.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from downloads.winrar.es and multiple other hosts.
MD5:
87c8c94685db1d697d2a8a13f47b36a1

SHA-1:
f3ea9e990117c718085aba55f2b2d5706765de3f

SHA-256:
b4959af209e4651748b4796f43f5fa9ccac84687be63e45cba9df343ba7291bd

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/27/2024 5:38:30 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW64.Paked
1.3.0.4959

Zillya! Antivirus
Trojan.Chifrax.Win32.4007
2.0.0.1921

File size:
1.8 MB (1,909,498 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\winrar-x64-50b2.exe

File PE Metadata
Compilation timestamp:
4/30/2013 11:07:13 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:UjiSY8lny+qeP1MIHqLLeeyIL9C5GXFrEzXY0:U2Joy+qiHqLLeeR16LX

Entry address:
0x20F74

Entry point:
48, 83, EC, 28, E8, 33, 58, 00, 00, 48, 83, C4, 28, E9, 12, FE, FF, FF, CC, CC, 48, 89, 5C, 24, 08, 48, 89, 6C, 24, 10, 48, 89, 74, 24, 18, 57, 48, 83, EC, 20, 49, 8B, E8, 48, 8B, F2, 48, 8B, D9, 48, 85, C9, 75, 05, E8, 81, 1A, 00, 00, 48, 63, 43, 18, 8B, 7B, 14, 48, 03, 46, 08, 75, 05, E8, 6F, 1A, 00, 00, 33, C9, 85, FF, 74, 33, 4C, 8B, 4E, 08, 4C, 63, 43, 18, 4B, 8D, 14, 01, 48, 63, 02, 49, 03, C1, 48, 3B, E8, 7C, 0A, FF, C1, 48, 83, C2, 08, 3B, CF, 72, EB, 85, C9, 74, 0E, 8D, 41, FF, 49, 8D, 14, C0, 42...
 
[+]

Code size:
168.5 KB (172,544 bytes)

The file winrar-x64-50b2.exe has been discovered within the following program.

WinRAR 5.00 beta 2 (32-bit)  by win.rar GmbH
WinRAR is a file archiver and data compression utility that supports RAR, and ZIP and can unpack ARJ, LZH, TAR, GZ, ACE, UUE, BZ2, JAR, ISO, EXE and 7z compressed archives. Version 5 uses the RAR5 archive format that cannot be managed by old versions of WinRAR.
www.rarlab.com
9% remove it
 
Powered by Should I Remove It?

The file winrar-x64-50b2.exe has been seen being distributed by the following 2 URLs.

Scan winrar-x64-50b2.exe - Powered by Reason Core Security