dofusinstaller.exe

$(^Name)

Ankama Games

The program is a setup application that uses the Nullsoft Install System installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
Ankama Games  (signed and verified)

Product:
$(^Name)

Version:
1.0.0

MD5:
0389b781cb7d9b3e4cd68f0d423ed56f

SHA-1:
c6234a2fd75f7342864d54beb7aa74002d3c050d

SHA-256:
ab5bc38e3af840efbe7b7e9524c3edfdda61c81ec17a0a80927c0518903fac6c

Scanner detections:
2 / 68

Status:
Inconclusive  (probably just false positive detections)

Analysis date:
4/23/2024 5:24:06 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.12.1.2

Trend Micro
PAK_Generic.005
10.465.02

File size:
6.4 MB (6,675,216 bytes)

Product version:
1.0.0

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\dofusinstaller.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/5/2013 2:00:00 AM

Valid to:
8/6/2015 1:59:59 AM

Subject:
CN=Ankama Games, OU=Editeur, O=Ankama Games, L=Roubaix, S=Nord, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1DAF2407E53BA7C004C253209A2EB841

File PE Metadata
Compilation timestamp:
1/5/2012 7:21:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
196608:WC7LUHf/wCWfZQRrSANBlaN0CaCmq+zAtzIss7PAb0Rq:XUHXw9/4lKgxqNIsGzq

Entry address:
0x4131

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 43, 43, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 44, 43, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 44, 43, 00, 56, A3, F4, 27, 43, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8B, 3B, 00, 00, A3, 50, 28, 43, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A9, B2, 40, 00, FF, 15, AC, 44, 43, 00, 83, EC, 14, C7, 44, 24, 04, AA, B2, 40, 00, C7...
 
[+]

Code size:
33.5 KB (34,304 bytes)

The file dofusinstaller.exe has been seen being distributed by the following 12 URLs.

https://dw.uptodown.com/dwn/KbYZWvN56cuiRwhaUqBF-6b9NKVte6wr5x8pQqvUOqUk4WHQno7zICRpOsgBECWaq3zMzVg4vMzeGpJSNrdLt9ItGLgfC5Wj6CNtcipbmBSAUY1DcEWG3psLd3ehoFFI/zfSiT-t11t6P2xGYD_vXglDwkPvl7nEg-DuEWtxVGK87Him5tHfY5Sk6p3EH1_xbQfdtOOw-QYhA6yibo0s1jYD4TPCE89rB-CSMpoziXegc4HqckhDG52iIoxzSxHgU/pYjpZ2T-Q2UzNK28U-4nq2x0IA5ncRESrODtjmVOz3bQ6ec39gk3rXkFljiiw4LS6t-fSfW5axyfIBPWysfeLt4I6AnyEGiLuDY6Sp1lfcv8JyB7Oe1UBDPkxpg3iSaY/.../

http://dw.uptodown.com/dwn/Q4ku_srGAeDqmIeyfUxGqtZE_sQssHO9yvxZNJ8Hx6i9y9HXL61oVIL6g7SGedD_SpPmAp0w6O3-BX8IroT8gx9Kwujz8bIT2sN_19iC7YptU3HeNaiv5HPlGHg13f4h/nzqsG1lGYGj_MOptguX76lJgiZXlmZva2r0x8_o-tO05YNBBxnNvSpAn_ajw-cvBcXX08PaUGb3Y0QPNlWJo4i3woTDpU2oqZTHP9QIy_Dv6k06JA8eDmRh00t6mQE0j/6m_RsSRXcrAkUTdjygJb9zoxWvEO1Xb3eVH8LRcjleH-dlnk1uNRvUZVtZG0Rvy07eru_x9gl5mcXzVYwfXcwavJMQQn3WWMgVKu59XZRuGPon-62if85T-_FCyBorX-/.../

Scan dofusinstaller.exe - Powered by Reason Core Security