WinRAR.exe

Alexander Roshal

WinRAR provides the full RAR and ZIP file support, can decompress CAB, GZIP, ACE and other archive formats. The file has been seen being downloaded from wetransfer-us1.s3.amazonaws.com.
Publisher:
Alexander Roshal

Description:
WinRAR archiver

Version:
3.50

MD5:
68b831063101ab845c7ae098aaf07be3

SHA-1:
7c667368b80226fb231654d6b41c6a56491cdd2c

SHA-256:
c6839d6fd5433e66d03c73809cab3cc4e9cef7f33d537291f8bf755295444004

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 7:36:19 AM UTC  (today)

File size:
860.5 KB (881,152 bytes)

Copyright:
Copyright © Alexander Roshal 1993-2005

Original file name:
WinRAR.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\winrar\winrar.exe

File PE Metadata
Compilation timestamp:
8/3/2005 9:31:38 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
12288:oMuWddCvcO2nRjZpzkbI5SHQBoCCVSpXcpa7815J4bBwiDMMMMMM:DuWd6cO2nL56Hhag1uBDMMMMMM

Entry address:
0x1000

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, B4, 81, 49, 00, A1, A7, 81, 49, 00, C1, E0, 02, A3, AB, 81, 49, 00, 52, 6A, 00, E8, D1, 61, 09, 00, 8B, D0, E8, A2, C2, 08, 00, 5A, E8, A4, B5, 08, 00, E8, 9B, C2, 08, 00, 6A, 00, E8, 98, D5, 08, 00, 59, 68, 50, 81, 49, 00, 6A, 00, E8, AB, 61, 09, 00, A3, AF, 81, 49, 00, 6A, 00, E9, A3, 42, 09, 00, E9, C6, D5, 08, 00, 33, C0, A0, 99, 81, 49, 00, C3, A1, AF, 81, 49, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, AC, 00, 00, 00, 0B, C9...
 
[+]

Entropy:
6.3238

Code size:
604 KB (618,496 bytes)

Shell Open Command
Open type:
WinRAR

Command:
"C:\Program Files\winrar\winrar.exe" "%1"


The file WinRAR.exe has been discovered within the following program.

WinRAR archiver  by win.rar GmbH
WinRAR archiver is a shareware file archiver that is able to create RAR archives natively.
www.rarlab.com
12% remove it
 
Powered by Should I Remove It?

The file WinRAR.exe has been seen being distributed by the following URL.

Scan WinRAR.exe - Powered by Reason Core Security