cabinst.exe

Scan cabinst.exe - Powered by Reason Core Security
MD5:
6b04a02f715b6cebe6296698ffc8d5f9

SHA-1:
41071ebe71555065dc694f48797c8e08f27c1377

SHA-256:
bda508231b86d26acba6795873f27b800da9f7535e99593fbfdee2fc38f557df

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/11/2016 12:54:26 PM UTC  (today)

Scan engine
Detection
Engine version

Kingsoft AntiVirus
Win32.Malware.Heur_Generic.A.(kcloud)
331020.49267

SUPERAntiSpyware
Trojan.Agent/Gen-Autorun[Swisyn]
10552

The Hacker
Posible_Worm32
6.8.0.6.161

File size:
90.5 KB (92,672 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\cabinst.exe

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
1536:HSJPKz6hLJj6oG1apw3Ly+44KhFNRz0S1HC14fx3WBG0UHYgiXdF:USzKPGgAyyKn4S1i1sDiX

Entry address:
0x39780

Entry point:
60, BE, 00, 40, 42, 00, 8D, BE, 00, D0, FD, FF, C7, 87, B4, A4, 02, 00, 3F, DD, CD, BD, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB...
 
[+]

Entropy:
7.8234

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
88 KB (90,112 bytes)

Scan cabinst.exe - Powered by Reason Core Security