rootrepeal.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from ad13.geekstogo.com.
MD5:
496f6f08509284abdd7f6253f7918eb9

SHA-1:
a0cf4c42bd673fb2952b8094a8e06bbefa47e39a

SHA-256:
5850663feba8839e866506386bffcd3f7965fe3a5c56701ba7c09841bd16ea7a

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/16/2024 12:43:19 PM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/Malware.QVM17.Gen
1.0.0.1015

File size:
129 KB (132,096 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\rootrepeal.exe

File PE Metadata
Compilation timestamp:
4/18/2010 3:04:55 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

CTPH (ssdeep):
3072:UnOgoTHHACx35nu1EDAxeWK/fZ7i1WSG5kX4zMN5y:+OgEnu1idr/fFEE3uy

Entry address:
0x1E59C

Entry point:
B8, F8, EE, 45, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 34, D7, 06, E9, 09, B9, 7E, 7E, 75, FA, D3, 27, C1, A3, C3, 0C, D0, 69, 37, 4F, 04, 61, 36, 04, 36, 28, 10, 33, E3, 96, 6F, 12, 26, 69, 3E, 0A, C9, 2B, B2, BB, 5D, C6, 14, 27, 54, 62, BE, 4A, 0D, 7C, 34, 77, C9, D5, E3, 4F, 27, 5B, A3, D5, 07, BE, DF, 27, C4, 76, EB, 11, D5, FD, 0C, 1A, D9, BC, 2F, 3C, C9, 23, 20, 06, B1, 08, 9C, 75, 2D, 0E, C1, 5C, 69, 98, 51, 4C, 9A...
 
[+]

Entropy:
7.9327

Packer / compiler:
PECompact v2

Code size:
172 KB (176,128 bytes)

The file rootrepeal.exe has been seen being distributed by the following URL.

Scan rootrepeal.exe - Powered by Reason Core Security