b1freearchiver_0.7.1.1636_inet.exe

Catalina Group Limited

The application b1freearchiver_0.7.1.1636_inet.exe by Catalina Group Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program B1 Free Archiver by Catalina Group Ltd.. The file has been seen being downloaded from pub.b1.org.
Publisher:
Catalina Group Limited  (signed and verified)

MD5:
4d5ee0e4a96e79ec9bd52734ce4fda84

SHA-1:
8ed672a6c8e53d2cc223e9569f1909bfcc8e312d

SHA-256:
5b5d1e4151f964a67306f055a933653a8a3b0c45b1c064c52e2d63e3b8547e8f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 1:12:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Catalina (M)
16.7.5.8

File size:
1.5 MB (1,582,440 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\b1freearchiver_0.7.1.1636_inet.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
9/26/2012 9:56:54 PM

Valid to:
9/26/2013 9:56:54 PM

Subject:
CN=Catalina Group Limited, O=Catalina Group Limited, L=Kwun Tong, S=Hong Kong, C=HK

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
27B940A1704DC9

File PE Metadata
Compilation timestamp:
12/7/2012 10:46:41 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:3vZ+rz5H2TO/qLrHxJ4WZFtaf5G7awtEZh7euaEyNwRj+X/dWK5c5aOkwXp06n2E:3vZ+rz5H8/HjlZLaf5G7awtEZh7euaEp

Entry address:
0x21A31

Entry point:
E8, CA, 9D, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B...
 
[+]

Entropy:
7.2380

Code size:
225 KB (230,400 bytes)

The file b1freearchiver_0.7.1.1636_inet.exe has been discovered within the following program.

B1 Free Archiver  by Catalina Group Ltd.
Publisher's description - “B1 archive is an open archive format, where best proven solutions were improved even more with new original ideas. It's free and available for both personal and commercial use. B1 Archiver is extremely simple to use, you don't need comprehensive manuals or guides.”
b1.org
45% remove it
 
Powered by Should I Remove It?

The file b1freearchiver_0.7.1.1636_inet.exe has been seen being distributed by the following URL.

Remove b1freearchiver_0.7.1.1636_inet.exe - Powered by Reason Core Security