aresgalaxy_appinstall_v2.3.0.3054.exe

Offercast Install Manager

This is a setup and installation application. The file has been seen being downloaded from www.dropbox.com and multiple other hosts.
Publisher:
Offercast Install Manager

Product:
Offercast Install Manager

Version:
2.3.2.267

MD5:
9af399fdfbf3d88b1bd7aa96f5abb4cc

SHA-1:
b155ba77fec140751064d716616b32924b8d084a

SHA-256:
13197566c2dfbd07f901ef4665aa5eacc3c7b11f8222abe55fe32dc52dabac95

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/29/2024 6:21:21 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.PCRat-1
0.98/21511

Qihoo 360 Security
HEUR/QVM05.1.Malware.Gen
1.0.0.1015

File size:
4.3 MB (4,553,216 bytes)

Product version:
2,3,2,266

Copyright:
Offercast Install Manager

Original file name:
Offercast Install Manager

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\downloads\aresgalaxy_appinstall_v2.3.0.3054.exe

File PE Metadata
Compilation timestamp:
3/17/2015 6:36:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:sOn7V1VZvHASRcrLH25ch9hPw84nbbrvveXMHQzsiPNcNeZWs/qjO4x5M1TZ5A49:sOn7V1VRqqm480NMWbjOwyv5u

Entry address:
0x3C325C

Entry point:
55, 8B, EC, 83, C4, F0, B8, 24, 58, 7B, 00, E8, 48, 83, C4, FF, A1, 74, E6, 7C, 00, 8B, 00, E8, 18, B5, D1, FF, A1, 74, E6, 7C, 00, 8B, 00, B2, 01, E8, 46, D2, D1, FF, A1, 74, E6, 7C, 00, 8B, 00, BA, CC, 32, 7C, 00, E8, 15, AF, D1, FF, 8B, 0D, 78, E6, 7C, 00, A1, 74, E6, 7C, 00, 8B, 00, 8B, 15, 64, 43, 7B, 00, E8, F9, B4, D1, FF, A1, 74, E6, 7C, 00, 8B, 00, E8, 3D, B6, D1, FF, E8, D4, 34, C4, FF, B0, 04, 02, 00, FF, FF, FF, FF, 19, 00, 00, 00, 4F, 00, 66, 00, 66, 00, 65, 00, 72, 00, 63, 00, 61, 00, 73, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.8 MB (3,940,352 bytes)

The file aresgalaxy_appinstall_v2.3.0.3054.exe has been seen being distributed by the following 2 URLs.

https://www.dropbox.com/s/.../AresGalaxy_appInstall_V2.3.0.3054.exe

Scan aresgalaxy_appinstall_v2.3.0.3054.exe - Powered by Reason Core Security