ymsgr900_2162_vn.exe

Yahoo! Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from w6.mien-phi.com.
Publisher:
Yahoo! Inc.

Description:
Yahoo! Messenger (Vietnamese)

Version:
9.0.0.2162

MD5:
aff9273f3f7448208987d671f5172012

SHA-1:
000cea4a51254c3ebbaebe4629111746616ad3e2

SHA-256:
8dc3a022125e5e7c0b02f54ff3f5459881f36b6bf1124f571cdcca7e232b19f1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/2/2024 11:30:17 AM UTC  (today)

File size:
14.6 MB (15,323,376 bytes)

Copyright:
1997-2008 Yahoo! Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ymsgr900_2162_vn.exe

File PE Metadata
Compilation timestamp:
4/9/1999 3:24:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:w5IK6ehBPjasvrSL3Hisqz0U4pLF8ZBUyflt49nhA+zw:khhBWgACsH2Ltszw

Entry address:
0x1000

Entry point:
F7, C0, DF, 75, 6E, E1, 84, E0, F7, C7, F4, 23, 47, 36, 86, FA, 32, EC, 85, FA, 89, CD, FF, C2, 0F, BE, F4, 04, 2B, FE, C2, 81, EB, 3F, 85, 00, 00, 08, F4, F3, C6, C6, 13, 89, E9, 86, F6, FF, CA, 8D, 3D, FF, D7, D5, EC, 38, CC, 71, 0B, 80, D1, 2B, 31, F6, 69, F6, C9, 30, D1, 4A, 0C, 0E, 69, DF, 2C, FF, 2E, 9C, E8, 5B, 00, 00, 00, BA, 90, 49, C6, 8B, 85, F7, 8D, 2D, 1F, 4D, 36, E4, 69, F5, AD, 69, E2, 95, C7, C5, 67, 6F, 87, DD, F6, C5, 06, B6, 73, 69, D2, 9E, B4, EB, E5, FE, C6, F7, C2, 01, 24, 32, 48, BB...
 
[+]

Entropy:
7.9983  (probably packed)

Code size:
512 Bytes (512 bytes)

The file ymsgr900_2162_vn.exe has been seen being distributed by the following URL.

Scan ymsgr900_2162_vn.exe - Powered by Reason Core Security