~SB1276.tmp

SetupBuilder

W.A.F.-Institut fuer Betriebsraetefortbildung

Publisher:
Lindersoft   (signed by W.A.F.-Institut fuer Betriebsraetefortbildung)

Product:
SetupBuilder

Version:
8, 0, 0, 1

MD5:
dc014c80a4e422aee785459978f10c16

SHA-1:
a906bcadc5a3cf20ff305fb677d2af4e86db9595

SHA-256:
ce5cab6bec749c6cf828d5a4cce41d5adff9a875609842b0011f6cd413fab764

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/14/2017 12:08:39 AM UTC  (today)

Scan engine
Detection
Engine version

Jiangmin
TrojanDropper.Injector.bhro
KV161010

Rising Antivirus
Malware.Heuristic!ET (rdm+)
23.00.65.161008

Zillya! Antivirus
Downloader.Adload.Win32.28318
2.0.0.3065

File size:
255.5 KB (261,616 bytes)

Product version:
8, 0, 0, 1

Copyright:
Copyright (C) 2012 Linder Software

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\~sb1276.tmp

Digital Signature
Authority:
The USERTRUST Network

Valid from:
10/1/2010 2:00:00 AM

Valid to:
10/1/2013 1:59:59 AM

Subject:
CN=W.A.F.-Institut fuer Betriebsraetefortbildung, O=W.A.F.-Institut fuer Betriebsraetefortbildung, STREET=Eugen-Friedl-Str. 6, L=Feldafing, S=Bavaria, PostalCode=82340, C=DE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00B013032B84E1D390C593CFFA44FDD1CD

File PE Metadata
Compilation timestamp:
6/6/2013 2:15:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:7lzfWCrtZwyTzd24YgupjWnUHlkyWZwIhXjAWnkAANQ:7ljLi2dnV/X5wCjRkAAC

Entry address:
0x1CE0

Entry point:
55, 8B, EC, 83, EC, 44, 56, FF, 15, 70, 20, 40, 00, 8B, F0, 8A, 06, 3C, 22, 75, 1F, 8A, 46, 01, 46, 84, C0, 74, 0F, 8D, 49, 00, 3C, 22, 74, 0D, 8A, 46, 01, 46, 84, C0, 75, F4, 80, 3E, 22, 75, 0D, 46, EB, 0A, 3C, 20, 7E, 06, 46, 80, 3E, 20, 7F, FA, 8A, 06, 84, C0, 74, 0C, 3C, 20, 7F, 08, 8A, 46, 01, 46, 84, C0, 75, F4, 8D, 45, BC, 50, C7, 45, E8, 00, 00, 00, 00, FF, 15, C4, 20, 40, 00, E8, 7A, 00, 00, 00, 68, 08, 30, 40, 00, 68, 00, 30, 40, 00, E8, 3B, 00, 00, 00, 0F, B7, 45, EC, 83, C4, 08, F6, 45, E8, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
4 KB (4,096 bytes)

Scan ~SB1276.tmp - Powered by Reason Core Security