atr_serv_53.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from buzzgsm.free.fr.
MD5:
3cdffdfa872c706fc5d9c4ae9a9e358d

SHA-1:
7d6e46b23365b7b51341cce58103c369f153147c

SHA-256:
d546bd9c0310b78f3d5734f2ca42f3affada30f2b1ec1fe098144ad0fc9a3bf8

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/19/2024 11:16:41 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
Suspicious
7.1.1

K7 AntiVirus
Trojan
13.174.10656

File size:
219 KB (224,256 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\atr_serv_53.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:8bOb3IeyIUw0F+rJrXsTMqKYxqT56cEM2egbnY:bjIHIUwnJjsTM5/T50

Entry address:
0x8F000

Entry point:
60, E8, ED, 10, 00, 00, C3, 83, 7B, A7, 58, C8, F7, 29, 1F, 0B, 75, E1, 29, 97, 87, 77, 67, 71, 5E, DF, 64, CD, 27, CA, D2, 36, C6, B6, 80, 5B, A6, 7A, 17, 46, A7, 92, 79, C6, F5, F6, E9, 15, 03, F4, 20, D4, BE, 5A, 16, 45, 18, 2D, A6, BE, A6, 26, 26, 26, 0B, 6F, 11, A5, A5, 25, D7, 88, 3B, 22, 02, A4, B0, 66, 84, 59, 2A, 6E, 17, 59, A3, 23, 58, 75, 70, A9, 63, 62, 65, 2E, 66, E5, BF, 7B, 7B, 8E, 84, 35, F5, 2D, A0, A3, B6, 44, 05, 3C, 7B, 24, 24, A4, 78, 30, 5F, 9B, 18, 22, 18, B8, 08, 79, 77, A1, 20, 9A...
 
[+]

Entropy:
7.9614

Packer / compiler:
tElock v0.71

The file atr_serv_53.exe has been seen being distributed by the following URL.

Scan atr_serv_53.exe - Powered by Reason Core Security