apptrans-setup.exe

AppTrans

iMobie Inc.

The executable apptrans-setup.exe, “AppTrans Setup ” has been detected as malware by 7 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.imobie.com.
Publisher:
iMobie Inc.

Product:
AppTrans

Description:
AppTrans Setup

Version:
1.9.0

MD5:
97ced2c2549d65f5179a232385bc609e

SHA-1:
8b0527415c5e50c2123834b472ccbf8781f5ff50

SHA-256:
9869a1e0b4c0ff8fa070f9f5d35d2defd17073e70676318ff9256188aed7121e

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/18/2024 9:46:22 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160518-2

AVG
Win32/Sality
2015.0.4591

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.225.531.0

Norman
Win32.Sality.3
19.05.2016 05:17:13

File size:
4.6 MB (4,787,912 bytes)

Product version:
1.9.0

Copyright:
iMobie Inc.

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\apptrans-setup.exe

File PE Metadata
Compilation timestamp:
7/9/2014 10:58:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:c3iwq6wAFTLmTVF3oc8mbMR5C/WiyRlNQiACFx80kFFF:cbJiTVFCmbMvC/3GXQMx80+FF

Entry address:
0x113BC

Entry point:
8A, DC, 05, D4, 98, BF, CC, 3B, EF, F7, C3, DC, 59, DD, 01, 84, D9, 8D, 3D, 42, 57, A5, DE, 57, 68, 05, 33, 93, 00, 46, 2B, F6, 71, 04, F3, C6, C7, 21, F3, 1D, 6B, 63, CD, 8E, B3, 84, 0F, AF, C9, 81, C6, 01, 00, 00, 00, 71, 05, FF, C0, 01, FB, 43, 71, 0A, 02, DC, 8D, 05, 69, 40, 55, 62, 2A, FC, 81, FF, DE, D1, 00, 00, 75, 05, 0A, E8, 0F, BF, C7, 0F, AF, C1, 81, FE, 48, 0C, 00, 00, 0F, 8C, BA, FF, FF, FF, F7, C2, 75, DB, 8D, D3, 80, E0, A5, 0F, AF, CB, E8, C7, 00, 00, 00, 39, CD, 8A, EF, 31, C0, B5, D5, 88...
 
[+]

Entropy:
7.9019  (probably packed)

Code size:
63.5 KB (65,024 bytes)

The file apptrans-setup.exe has been seen being distributed by the following URL.

Remove apptrans-setup.exe - Powered by Reason Core Security