winrar-x64-393d.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from dl.cdn.chip.de and multiple other hosts.
MD5:
988a080457c26c84fb6efe1acbae7951

SHA-1:
e8a995053a7e3fab8e0312ac3bb0cb5fdf4dd242

SHA-256:
4d5bb829ed6a15f324d9989defb9930466bdf4b93fd95f80bb2f285aba1c1346

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 9:28:57 PM UTC  (today)

File size:
1.5 MB (1,618,487 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\winrar-x64-393d.exe

File PE Metadata
Compilation timestamp:
3/15/2010 7:28:11 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:OLNwysiW6TIbG5aJecFhoyYXF4OHxoq2Rb:IN3siW6w5J3FU1zRorb

Entry address:
0xACE8

Entry point:
48, 83, EC, 28, E8, 9B, FE, FF, FF, 45, 33, C9, 45, 33, C0, 33, D2, 33, C9, 48, 83, C4, 28, E9, 90, 37, 00, 00, 48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, F9, 48, 89, 11, 48, 8B, CA, 48, 8B, DA, E8, 41, A2, FF, FF, 48, 89, 47, 08, 8B, 83, 24, 0C, 00, 00, 48, 8B, 5C, 24, 30, 89, 47, 10, 48, 8B, C7, 48, 83, C4, 20, 5F, C3, CC, CC, 48, 83, EC, 28, 4C, 8B, 09, 41, 8B, 81, 24, 0C, 00, 00, 39, 41, 10, 75, 0F, 48, 8B, 51, 08, 45, 33, C0, 49, 8B, C9, E8, 52, A8, FF, FF, 48, 83, C4, 28, C3, CC, 48, 83, EC, 68...
 
[+]

Code size:
73 KB (74,752 bytes)

The file winrar-x64-393d.exe has been discovered within the following program.

WinRAR  by win.rar GmbH
WinRAR is a shareware file archiver and data compression utility that is able to create RAR archives natively. WinRAR supports RAR (WinRAR native conversion format) and ZIP archives, and unpacking of ARJ, LZH, TAR, GZ, ACE, UUE, BZ2, JAR, ISO, EXE, 7z, and Z archives.
www.rarlab.com
4% remove it
 
Powered by Should I Remove It?

The file winrar-x64-393d.exe has been seen being distributed by the following 3 URLs.

http://dl.cdn.chip.de/downloads/.../winrar-x64-393d.exe

http://www.rarlab.com/.../winrar-x64-393d.exe

Scan winrar-x64-393d.exe - Powered by Reason Core Security