ymsgr1150_0228_vn.exe

Yahoo! Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from w6.mien-phi.com.
Publisher:
Yahoo! Inc.

Description:
Yahoo! Messenger (Vietnamese)

Version:
11.5.0.0228

MD5:
d37c1ffc4e23b1235e08baae50651c82

SHA-1:
70d6610862eb2957aec4c6d0a1047dc6cb5250e1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/2/2024 11:21:41 AM UTC  (today)

File size:
18.7 MB (19,607,896 bytes)

Copyright:
1997-2010 Yahoo! Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\ymsgr1150_0228_vn.exe

File PE Metadata
Compilation timestamp:
4/9/1999 4:24:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:jGWzp6dv0Z70r9wN8eWfjhPyoAkvhecHYlZrkyH+kMBxd:jGWzpbKx8cj5ylkvtgk3d

Entry address:
0x1000

Entry point:
60, 89, DF, FE, C2, 69, C7, 23, B1, D7, F9, 87, FD, 81, FD, 52, ED, 00, 00, 74, 04, 33, CB, 2C, A9, 8D, 0D, 06, 29, 55, 85, EB, 09, 4F, 69, F5, 05, 0E, 53, 76, 2A, C3, 81, FB, DC, D5, 00, 00, 69, DD, EE, 57, 0B, 64, 71, 08, FF, CF, 69, F7, 65, 8D, 64, 8A, 42, 85, F9, F7, C6, 7D, E4, 8C, 29, 4D, 0F, AF, FF, 49, 0F, AF, EB, 8D, 0D, 32, D1, C8, 36, 68, 14, 11, 00, 00, 84, E0, F6, C2, E9, 58, 81, FF, 2F, F6, EB, 12, 8B, F8, FE, C2, 2D, 5B, 09, 00, 00, EB, 07, 89, F6, 0F, BF, E8, FF, CB, 8A, D7, 80, D3, B0, 69...
 
[+]

Entropy:
7.9974  (probably packed)

Code size:
512 Bytes (512 bytes)

The file ymsgr1150_0228_vn.exe has been seen being distributed by the following URL.

Scan ymsgr1150_0228_vn.exe - Powered by Reason Core Security