wrar531.exe

The executable wrar531.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from winrar.ar.softonic.com.
MD5:
0635b50c3dbed67f715a7ef712575fbb

SHA-1:
78d3adc10e2a53cbf29791d0ea316badd8ff77ec

SHA-256:
17f184ef81a19303adfd73aec03e493ffb517724a6ce4ae7d417f8d1d22a0e4a

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/26/2024 10:46:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Generic.Variant
16.7.31.0

File size:
1.8 MB (1,916,136 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\wrar531.exe

File PE Metadata
Compilation timestamp:
2/3/2016 9:38:36 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:dIbJmvPav5tq8HBcxDzNBBjJcLN247+GUKm7ci:dItUav5xHBEBjJcLT7lUKhi

Entry address:
0x1E06B

Entry point:
EB, 07, 0F, AF, D7, 34, 25, 28, C8, C6, C3, 96, FE, CB, 8D, 15, 44, 60, 5B, B8, 0F, B6, EE, 89, DA, 87, C0, 8B, C9, 84, FC, C7, C2, 9B, A0, B5, 49, 87, D7, FE, CE, FE, CB, 80, EF, F6, 8D, 0D, B8, 69, DD, 49, E8, 1A, 00, 00, 00, C6, C0, 49, 80, CD, 3D, BD, CF, D7, 2A, 5F, F7, C7, F7, 2A, FB, 66, 8A, E7, BE, 4D, 1B, B7, 1F, 3B, FB, 85, D5, 8A, CD, F3, F6, C0, FD, F3, 71, 08, 69, F7, 7E, 19, 31, AE, FF, C6, 35, 49, D5, 00, 00, 8D, 3D, D1, F5, 37, E6, 5D, 8D, 35, 65, D7, B1, 2F, F7, C7, 11, 4F, 42, 25, FF, C9...
 
[+]

Entropy:
7.9336  (probably packed)

Code size:
164.5 KB (168,448 bytes)

The file wrar531.exe has been seen being distributed by the following URL.

Remove wrar531.exe - Powered by Reason Core Security