xamarininstaller.exe

Win

The executable xamarininstaller.exe has been detected as malware by 8 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from activation.xamarin.com.
Publisher:
Microsoft*  (Invalid match)

Product:
Win

Version:
1.00

MD5:
5f357b2bbf8cc94d117f22860f921760

SHA-1:
ca26f192c95ab3e597bda7b488da892562c51d7a

SHA-256:
88a520a013ea5fb419f3cdbb469ea1581c2414548a45a2436a5c6b04f35a53f2

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
11/24/2024 9:51:04 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160209-2

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Swisyn.ag
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.6208.0

Norman
Win32.Sality.3
08.02.2016 04:24:12

VIPRE Antivirus
Threat.4721115
46800

File size:
2.5 MB (2,591,481 bytes)

Product version:
1.00

Original file name:
Win.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\xamarininstaller.exe

File PE Metadata
Compilation timestamp:
6/14/2011 12:01:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:HYbrHpHzrWf5C7XWiE3wYxU9k0x3pm3uA+VR3Yky:435fWAZlq8/x5JA+V1Yky

Entry address:
0x3670

Entry point:
0F, AF, F2, 69, C3, BD, 4B, 8D, 88, 43, 69, C1, B0, 1C, 02, BF, 0F, AF, F8, F3, 0F, AF, F5, F2, BE, 05, 4E, 11, CA, FE, CF, 05, 76, A9, B4, E6, 81, F7, 5B, 16, 00, 00, F3, 85, DA, 0C, 66, 42, 81, FE, 66, B7, 00, 00, 70, 06, 69, F7, C6, CF, A3, 1E, 05, E1, A4, 42, D5, BB, E2, 7E, D4, 46, 51, 68, B5, E9, 32, 00, 81, FA, 83, 55, 00, 00, 73, 0A, 33, ED, C7, C5, BB, E1, 8A, EE, 8A, D5, E8, B9, 00, 00, 00, 85, F3, 71, 01, F3, 8D, 0D, 4C, 61, D7, DF, 8A, C9, 74, 06, 8D, 05, F0, 8B, DC, 6A, 0F, B6, C3, 81, CF, BB...
 
[+]

Entropy:
7.7737  (probably packed)

Code size:
172 KB (176,128 bytes)

The file xamarininstaller.exe has been seen being distributed by the following URL.

Remove xamarininstaller.exe - Powered by Reason Core Security