desktopmania-setup.exe

OOO Online Center

This is a self-extracting archive and installer. The file has been seen being downloaded from download.desktopmania.ru.
Publisher:
OOO Online Center  (signed and verified)

MD5:
ba8487cbeb9bf508910471b7ec417dc4

SHA-1:
363c689c34152fde851510f52cacf1c0871a6cb0

SHA-256:
d6a133990b0497b320e89f2e8a94cac8739c9edb3217afafca1914b649d2b043

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/23/2024 10:02:20 AM UTC  (today)

Scan engine
Detection
Engine version

Norman
Troj_Generic.VXTUV
11.20141015

Qihoo 360 Security
Malware.QVM05.Gen
1.0.0.1015

File size:
396.9 KB (406,400 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\desktopmania-setup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/11/2013 4:00:00 AM

Valid to:
2/11/2016 3:59:59 AM

Subject:
CN=OOO Online Center, O=OOO Online Center, L=Yaroslavl, S=Yaroslavl, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4945BBB8ACAA7493A28ADEA6404F38DB

File PE Metadata
Compilation timestamp:
8/15/2014 4:35:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:+itl4SQlc4FMxapAyN7uJgPZ9yF/fwZaFk/:J1eLDpj5uJ6jyB7Fk/

Entry address:
0x131F0

Entry point:
55, 8B, EC, B9, 0B, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, 68, 26, 41, 00, E8, 34, 27, FF, FF, BF, 70, BB, 41, 00, 33, C0, 55, 68, 30, 36, 41, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 38, FE, FE, FF, 8B, 45, EC, BA, 48, 36, 41, 00, E8, A3, 14, FF, FF, 75, 0A, 68, 00, 7C, 01, 00, E8, 7F, 27, FF, FF, 68, 64, BA, 41, 00, 68, 04, 01, 00, 00, E8, D0, 27, FF, FF, 8D, 45, E8, BA, 64, BA, 41, 00, B9, 05, 01, 00, 00, E8, E2, 12, FF, FF, FF, 75, E8, 68, 60, 36, 41, 00, 68, 90...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
72 KB (73,728 bytes)

The file desktopmania-setup.exe has been seen being distributed by the following URL.

Scan desktopmania-setup.exe - Powered by Reason Core Security