shareaza_setup.exe

Discordia Limited

The application shareaza_setup.exe, “Shareaza ” by Discordia Limited has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from download.cdn.shareazaweb.com.
Publisher:
Discordia, LTD   (signed by Discordia Limited)

Description:
Shareaza

Version:
8.0.0.123534

MD5:
9105166565f5e19000a6f0da21072ada

SHA-1:
f4bb3e337c0ec3670c8b648741ea4562e7e63877

SHA-256:
a3c40cdcb803bab2ff0f5eaa194d9548f8b3d74ec240e945ec7e6915f41b3c2e

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 12:01:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.DiscordiaLimited.O
14.6.23.1

Trend Micro House Call
TROJ_PAM_0000050629.T3
7.2.174

File size:
2.2 MB (2,358,248 bytes)

Copyright:
Copyright (c) 2011

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\shareaza_setup.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/23/2010 8:00:00 AM

Valid to:
7/15/2012 7:59:59 AM

Subject:
CN=Discordia Limited, OU=SECURE APPLICATION DEVELOPMENT, O=Discordia Limited, L=Limassol, S=Limassol, C=CY

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
365134344F55842D5CCE133A8C629064

File PE Metadata
Compilation timestamp:
4/16/2009 4:43:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
49152:9wMLUkvdRI/MPnzAQMPNQqy19oN2Z0lVWZP+Hf6tbwU/:9wMLUghPn/M1QqyUN2Z0lsZGlU/

Entry address:
0x12A70

Entry point:
6A, 60, 68, B8, A2, 41, 00, E8, C0, 03, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 28, 18, 00, 00, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, E8, A0, 41, 00, 8B, 4E, 10, 89, 0D, 24, 0D, 42, 00, 8B, 46, 04, A3, 30, 0D, 42, 00, 8B, 56, 08, 89, 15, 34, 0D, 42, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 28, 0D, 42, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 28, 0D, 42, 00, C1, E0, 08, 03, C2, A3, 2C, 0D, 42, 00, 33, F6, 56, 8B, 3D, A8, A1, 41, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
7.9158

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
96.5 KB (98,816 bytes)

The file shareaza_setup.exe has been seen being distributed by the following URL.

Remove shareaza_setup.exe - Powered by Reason Core Security