rufus-2.7.exe

Rufus

Akeo Consulting

This is a setup program which is used to install the application. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
Akeo Consulting (http://akeo.ie)  (signed by Akeo Consulting)

Product:
Rufus

Version:
2.7.855

MD5:
45f58b0ef0674f3f43ee106a2e276425

SHA-1:
baa25eca0e8dc87c99b5a4702036ebb70a2af1d6

SHA-256:
7eac92c4165577c76ed22c389b64e4b32979fb216699c52c64c39bdf0c833b17

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/27/2024 3:25:00 AM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM18.1.Malware.Gen
1.0.0.1120

File size:
861.3 KB (881,920 bytes)

Product version:
2.7.855

Copyright:
© 2011-2016 Pete Batard (GPL v3)

Trademarks:
http://www.gnu.org/copyleft/gpl.html

Original file name:
rufus.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\rufus-2.7.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/12/2012 1:00:00 AM

Valid to:
11/13/2017 12:59:59 AM

Subject:
CN=Akeo Consulting, O=Akeo Consulting, STREET="24, Grey Rock", L=Milford, S=Co. Donegal, PostalCode=Co. Donegal, C=IE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
47D73D146614770CB3DAAF5502C48D9C

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:YCDHR1z3lubUbRQGcAebSqWapkhHn1QkQHT+EuQDW:Y+PTMbUbRGnbBGHN8Cca

Entry address:
0x23F430

Entry point:
60, BE, 15, 60, 57, 00, 8D, BE, EB, AF, E8, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 1E, D9, 23, 00, 57, 83, C3, 04, 53, 68, 0B, 94, 0C, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
812 KB (831,488 bytes)

The file rufus-2.7.exe has been seen being distributed by the following 50 URLs.

http://dw.uptodown.com/dwn/L5wLK5oOBsAtRAoolw_WOgIALaOO8sZFD--8ilLlwdH4wAvrNG9djlCbTUQ67HG35EmfZcpO7vB2egbVpJknv87fSClxS1AS1EzOtRedgdVgLmVdCItf8uQ3AEza_h-j/DsgaXku_Am6wQKxCqIGHJeAx0WImQ3JRkzU7tkX03_W6RpTEDZUQ6y7TPPh4A4H4le9E8zKy3gqQegCDGJVlsfcHDfK38R4a6tPzICw55uTpQ7BGQMv11GE7P9TbGPoP/.../

http://dw.uptodown.com/dwn/RBAMdjXCfg50cVE17KxulUX-rpUF7kT5UmEfSdm_XSqWp0MIiMkZe6sd-wLqjsVben7qH9NtnD5HTkO2UlNRi2Z7X-TURQfip5hJgvZHUNxO-g5w9UGr_NYHl4YaBGjt/egfed0hIaIw6vhg0ojIfZEBDmT1iIbO1aLqYOBoiRCwQNP7oaahSquJ5HbURcVUTrtlatasJb3YQOvi5iWlBtgtRMLzygdsr1g6rHXdIAURgbNXAw-lypwf-pC2knk5I/.../

http://www.techspot.com/downloads/downloadnow/.../?evp=6c8065dabaf305a1353b22f5790fdf53&file=1

https://docs.google.com/uc?id=0Bxs9UxDhWKxiaVdWUlg1UEpXak0&export=download

http://www.softportal.com/getsoft-30994-rufus-1.html

http://www.techspot.com/downloads/downloadnow/.../?evp=caefc0099d57d52e5894b936b8701599&file=2

about:internet

http://www.downloadcrew.com/?act=software.download&id=30840&t=1457602483&c=b0dd31f559ecdbe94ee799d08e1ff2718773f6a3

http://dw.uptodown.com/dwn/_eeF3bIv0AdQiPuL1OpTNHhNkf8lKdcdvQFpBvFe-JH9ySfNVddo4KHyd5UiyQyVc0dzSgVHEo82W2G6NQtdHAB-25dbELZITkCpfV6W3TvZVOngYz3BocEysCKUNxeQ/uSZdxCbAeLE4I3Va8EG-L390WrCjmSlrfMfKU_N-CMBQtD3VPYyiri8yC6ppfbkacHR9ePdBrG49Vi_gIbIQtjT3Xbb22LIqIh9zL6f3rltKLTCRVbXAqSg4g-03jNgg/.../

http://www.downloadcrew.com/?act=software.download&id=30840&t=1459859128&c=91d72ebe0d7fbe90de8f36f0fad3e1443f37117c

http://dw.uptodown.com/dwn/84OORv5iueHdimIFLruNry0rxCDvc2oyFQ2Z2IbW3s1R1Xq-KSRhIzjkVo0jEzmnXPu7xVwN-nIz3eKjZZGMMhjZU13eXU9r77CFUY7fPcP_9Yi8bLqTmtyAAbTq9r3a/zLA06JTjc33hNDl2j4vHEUfwKC_ESsYTdxwR6zatQMs3xFqjO2okLfnbngT6_6u-8Yfh-wYscmdF8yyq9fCMycqMvjji3YOUzQ9ZPZWvYdD9Tzah0vUeCcpT1jrbIZgW/.../

https://mega.nz/temporary/.../Z552iSRQ

http://dw.uptodown.com/dwn/R9GFmBCrhZjbSJS05H9TSDUOA3yKQ2cBTr9L0re-Zn4kTsXJ8KKb4eUwCWK7hK6i6MNwrfteiIZbZUy3NZKlEkufDaACTMi_WWyoyTDQBcV-UOJ9XXEZmU3hnidvtqNt/qwr3QX89VWLuL9LhoGENH59ZNxRovSoWzykx4NQeZIEGWBNT0ktBB3iddldIBcC1FTHm0PLcVQpWRBkW2-mjRZNelUaF535bijZLUlLEZoe1MSOK5SuJsGaH1IL66mm2/.../

https://docs.google.com/uc?authuser=0&id=0Bxs9UxDhWKxiaVdWUlg1UEpXak0&export=download

http://blogattach.naver.net/40d55cecf9a3a47856b5d5e3df3b4b3e9ccb34d1e7/20160311_263_blogfile/.../rufus-2.7.exe

http://www.techspot.com/downloads/downloadnow/.../?evp=a32132e834c9f8abb9229bd16aa99a3a&file=1

http://192.168.43.1:33455/static/storage/emulated/0/.../rufus-2.7.exe

https://mega.nz/persistent/.../hRNBDBAS

http://dw.uptodown.com/dwn/JYGnR-un9YNCuDcOa8pBYu5DT5MjgaxU9FfFlHVK53_h_8f5L7KzsnxdU63Qc8XjsnEYJsxu1hNcWvvVWbmy7eVc1fuGBhj0dZ-Ys3pYQGlmvt73BmG4gElJ1a9fHPMy/ocb6cwX0Ddh7sjQ4d9c8oJbSL1aAtWHOT-rEeLibvXzLuc5Y8YXqarS24WuV5G-RO3GIJdvAmYsivTfPWCfZWIoHhn0lKYVY-ny3O7iBMzI9bFcVg1xNeIoYGhv1Fiz8/.../

http://85.25.41.248/.../rufus-2.7.exe

https://mega.nz/temporary/.../hRNBDBAS

Latest 30 of 82 download URLs

Scan rufus-2.7.exe - Powered by Reason Core Security