setup 4.5.8.exe

The executable setup 4.5.8.exe has been detected as malware by 18 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from s10217.chomikuj.pl.
MD5:
bc2a950558a85ff915a3e804a2e7cf48

SHA-1:
2d39f6b4e592349c15db9cc0c5e5cad0af53d2d8

SHA-256:
c7b5ae5cf9127467ebc2d228750ca6966f51c4cc193afd5eed4d3cd9546fc069

Scanner detections:
18 / 68

Status:
Malware

Analysis date:
5/13/2024 5:34:29 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Chifrax.C.584
7.11.31.202

avast!
Win32:RarMod [Drp]
2014.9-160303

AVG
Generic13
2017.0.2816

Comodo Security
TrojWare.Win32.Trojan.Chifrax.~c
12491

Dr.Web
Trojan.MulDrop2.1537
9.0.1.063

Emsisoft Anti-Malware
Trojan.Win32.Chifrax!IK
8.16.03.03.02

Fortinet FortiGate
W32/Chifrax.C!tr
3/3/2016

G Data
Win32:RarMod
16.3.22

IKARUS anti.virus
Trojan.Win32.Chifrax
t3scan.1.1.118.0

K7 AntiVirus
Trojan
13.140.6976

Kaspersky
Trojan.Win32.Chifrax
14.0.0.574

McAfee
Artemis!BC2A950558A8
5600.6472

Microsoft Security Essentials
PWS:Win32/Tibia.AK
1.163.1557.0

Norman
W32/Suspicious_Gen2.KDTEZ
11.20160303

nProtect
Trojan/W32.Chifrax.2391668
12.06.03.01

Trend Micro House Call
TROJ_GEN.R4FH1LN
7.2.63

Vba32 AntiVirus
Trojan.Chifrax.c
3.12.16.4

VIPRE Antivirus
Trojan.Win32.Generic
12002

File size:
2.3 MB (2,391,668 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup 4.5.8.exe

File PE Metadata
Compilation timestamp:
9/13/2006 8:20:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
49152:yZYVvzrog7ZA5EtBRAt9WLeHdL5AcgWja4qp56LEZD1R8H/qbCs:3vN7m5KnAtc6gcUc2pRH3

Entry address:
0x1000

Entry point:
E8, 9F, 28, 00, 00, 50, E8, 83, 2A, 01, 00, 00, 00, 00, 00, 90, 55, 8B, EC, 53, 56, 57, 8B, 7D, 10, 8B, 5D, 0C, 8B, 75, 08, 8B, D3, FF, 75, 14, 68, E5, 40, 41, 00, 6A, 00, 6A, 00, 8B, C6, 8B, CF, E8, 2A, 44, 00, 00, 81, EB, 10, 01, 00, 00, 74, 05, 4B, 74, 14, EB, 57, FF, 75, 14, 6A, 66, 56, E8, DA, 2C, 01, 00, B8, 01, 00, 00, 00, EB, 47, 66, 81, E7, FF, FF, 66, FF, CF, 74, 07, 66, FF, CF, 74, 23, EB, 30, 68, 80, 00, 00, 00, 68, E0, 50, 41, 00, 6A, 65, 56, E8, 20, 2C, 01, 00, 6A, 01, 56, E8, FA, 2B, 01, 00...
 
[+]

Code size:
76 KB (77,824 bytes)

The file setup 4.5.8.exe has been seen being distributed by the following URL.

Remove setup 4.5.8.exe - Powered by Reason Core Security