winrar.exe

MD5:
8149b29308131af98654e3e2f129198b

SHA-1:
755a587fb371c24eded4abe8844bb92c75a7a22f

SHA-256:
d3cf49a7ac726ee27eae9d29dee648e34cb3e8fd9d494e1b347209677d62cdf9

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 3:39:18 PM UTC  (today)

Scan engine
Detection
Engine version

Fortinet FortiGate
W32/Zbot.AAQ!tr
4/3/2014

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.14401

Sophos
Mal/EncPk-NS
4.98

File size:
260.5 KB (266,752 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\winrar.exe

File PE Metadata
Compilation timestamp:
6/4/2005 10:31:15 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
1.64

CTPH (ssdeep):
3072:9WL5U9MGcDrMfit9D3zmoB8fds3cZUr7u5M9vD3:9IzdQit9e5HOr7u5M9vD3

Entry address:
0x1000

Entry point:
83, 05, 2C, 12, 45, 00, 54, 68, C4, 18, 45, 00, FF, 15, 7F, 14, 46, 00, 68, C1, 0E, 00, 00, FF, 15, 1B, 15, 46, 00, 68, B4, 1F, 45, 00, FF, 15, 1B, 15, 46, 00, 0F, 85, CB, 00, 00, 00, 75, 2F, 03, 05, 48, 13, 45, 00, 80, 35, C0, 1A, 45, 00, 2A, 8B, 3D, 70, 1F, 45, 00, C6, 05, FC, 10, 45, 00, 02, 6A, B1, 8B, 35, 88, 15, 45, 00, 5B, 89, 3D, E4, 19, 45, 00, 8B, 15, 44, 16, 45, 00, 66, BE, AA, C0, 83, C7, 4C, 83, FA, A1, 75, 08, 4B, 89, 1D, 78, 12, 45, 00, 4B, 83, FA, 47, 74, 06, 89, 35, C0, 10, 45, 00, 89, 1D...
 
[+]

Entropy:
6.1133

Code size:
211 KB (216,064 bytes)

The file winrar.exe has been seen being distributed by the following URL.

Scan winrar.exe - Powered by Reason Core Security