Necro SP Installer.exe

This is a setup and installation application. The file has been seen being downloaded from fs09n4.sendspace.com and multiple other hosts.
Version:
0.0.0.0

MD5:
e70075dbbf603312a0170053611b7577

SHA-1:
07139b98356b3a27c6692a5318563843260d73b8

SHA-256:
25eefa738658558701d3333d94a0e6dedd1114d9ec3eed2d9af21dd1e551d002

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 9:18:57 PM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.0.127

File size:
4.1 MB (4,250,112 bytes)

Product version:
0.0.0.0

Original file name:
Necro SP Installer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\necro sp installer.exe

File PE Metadata
Compilation timestamp:
7/2/2013 6:10:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:8ANhgyKciTkq6gdsBrgsB0ogg+7qiVvNjpoQ7ed21a:1izoq6UorNB0ngcqiVo4s21a

Entry address:
0x40EE3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9999

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
4.1 MB (4,247,552 bytes)

The file Necro SP Installer.exe has been seen being distributed by the following 4 URLs.

https://fs09n4.sendspace.com/dl/924fd315377fa3b58b07b16f93b97206/56bfc3b362a69ef8/.../Necro SP Installer.exe

https://fs09n1.sendspace.com/dl/d5b714dcf78114f83fe1e8737430814d/57a909160aade334/.../Necro SP Installer.exe

Scan Necro SP Installer.exe - Powered by Reason Core Security