carculator v1.10.exe

Carculator

Cipres

The executable carculator v1.10.exe has been detected as malware by 6 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from s6015.chomikuj.pl.
Publisher:
Cipres

Product:
Carculator

Version:
1.00

MD5:
4f3a91693d1ec2a4ba96ebffd1176c11

SHA-1:
8bdc9f4bbd8923a6ef5838f130f063e4bb914420

SHA-256:
e37942ae25b437c471597190bb06911356a2dc8f81709ec7593962418257952f

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
5/17/2024 2:20:57 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

AVG
Win32/Sality
2015.0.4604

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.225.1925.0

File size:
3.5 MB (3,645,440 bytes)

Product version:
1.00

Original file name:
Carculator.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\documents and settings\wspólne\moje dokumenty\downloads\carculator v1.10.exe

File PE Metadata
Compilation timestamp:
6/8/2008 7:31:43 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
83.82

CTPH (ssdeep):
98304:nFn9cHOWLxlBuGiwNmNWLSiHTAUYTZkb64D/cZXjBixfhukiUpxUexRe6i4GtvRQ:nFn9cHOWLxlBuGiwNmNWLSiHTAUYTZk/

Entry address:
0x3B64

Entry point:
8B, FE, 88, C5, BB, E1, ED, 0B, 2E, 68, F2, DC, 76, 00, 68, 6F, B2, 03, 00, 81, FB, AB, CE, 00, 00, 71, 01, 48, 33, F2, 0F, BE, DD, 84, CB, C7, C0, CF, 56, CD, 5E, 84, EE, 23, F7, 86, E0, 03, F0, 81, F9, B1, 73, 00, 00, 69, F5, 46, C1, 5F, 5E, 69, CB, 01, 02, FD, B2, F2, 3A, DC, 89, D8, FF, CD, E8, 81, 00, 00, 00, 2C, A3, 2D, 63, C7, 95, 4F, 85, F3, 69, D9, 81, D8, 50, 65, B0, 5C, 02, C9, 84, E5, 3B, D1, 2B, DB, 3D, CD, B4, 00, 00, 77, 06, 8D, 3D, E8, B0, 97, F7, F2, EB, 03, C6, C5, D8, 34, F1, FE, C2, BE...
 
[+]

Code size:
316 KB (323,584 bytes)

The file carculator v1.10.exe has been seen being distributed by the following URL.

Remove carculator v1.10.exe - Powered by Reason Core Security