wrar531.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from files.downloadnow-1.com.
MD5:
ce2a6456bc61ff065d1f720143c5391d

SHA-1:
9c038e393eddf8809b9d136e4d4204ac82ff877c

SHA-256:
6b4e48276f7ecf773b77c2ee5343173dca8a771313620391433152de7a011a8e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/24/2024 4:44:14 PM UTC  (today)

File size:
1.8 MB (1,884,152 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\wrar531.exe

File PE Metadata
Compilation timestamp:
2/3/2016 9:38:36 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:qIUXv4OSSMbaD24PCCvlYxl7c9/cmovV2dGaN6lXZce:qBXfS6D24PCCdYC/4uHQ8e

Entry address:
0x1E06B

Entry point:
60, 89, DD, 69, C2, AA, 81, 10, D1, 8D, 3D, 16, AF, AC, 2A, 8D, 2D, 1D, A0, 0D, 2E, BF, 23, AE, D0, A5, EB, 05, 3A, E7, 0F, B7, FD, 78, 08, 8D, 15, 71, 8B, 1C, 87, 85, DB, 51, 52, 85, E9, E8, 1C, 00, 00, 00, 0F, AF, DB, 84, C7, 32, D3, 84, E9, 0F, B7, F6, 03, CD, 69, EF, 10, DF, 38, 75, 0F, BF, D3, 33, C3, 0F, B7, D2, 83, E7, 00, 11, EA, 89, C3, 89, E8, F6, C1, F4, 02, CA, 84, FF, 81, FE, FA, F0, 00, 00, 77, 01, 4D, 45, 0F, BE, D0, 0F, BF, D1, 33, C0, 85, C7, 35, 77, 80, F1, FF, 49, 05, 24, 71, 0E, 00, 69...
 
[+]

Entropy:
7.9525  (probably packed)

Code size:
164.5 KB (168,448 bytes)

The file wrar531.exe has been seen being distributed by the following URL.

Scan wrar531.exe - Powered by Reason Core Security