nanoav.free.setup_2.exe

NANO Antivirus

NANO Security Ltd

This is a setup and installation application. The file has been seen being downloaded from nanoav.ru.
Publisher:
NANO Security  (signed by NANO Security Ltd)

Product:
NANO Antivirus

Description:
NANO Antivirus setup

Version:
1.0.38.4417

MD5:
741fb8ccacfdf8c3725c693aa0db148f

SHA-1:
a98e8b139714a764f52f24e9018b82d20b67996a

SHA-256:
77acae7467dbe2ed9261343c203030f89b62e222f210a8daa0b101405354e4a2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 11:18:38 AM UTC  (today)

File size:
8 MB (8,342,128 bytes)

Product version:
1.0.38.74417

Copyright:
Copyright (C) 2009 NANO Security

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\Music\nanoav.free.setup_2.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
5/26/2016 6:59:41 PM

Valid to:
5/27/2017 3:36:12 PM

Subject:
CN=NANO Security Ltd, O=NANO Security Ltd, L=Bryansk, S=Bryansk Oblast, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
59AFDE3D8D0DCFF6689875D4

File PE Metadata
Compilation timestamp:
6/3/2015 4:02:03 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:oQ56idSgKDsBqNqv/4B5z4Ng2hnlDX7hvpm8zv7H3WO5tNxMpZg3:FjVKWoqGCJ1vpTztNx6g3

Entry address:
0x1154

Entry point:
E9, 6A, 34, 00, 00, E9, 64, 62, 00, 00, E9, C4, 82, 00, 00, E9, 02, 63, 00, 00, E9, 07, 62, 00, 00, E9, 00, 6A, 00, 00, E9, 5A, 63, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
7.9856

Packer / compiler:
Xtreme-Protector v1.05

Code size:
42 KB (43,008 bytes)

The file nanoav.free.setup_2.exe has been seen being distributed by the following URL.

Scan nanoav.free.setup_2.exe - Powered by Reason Core Security