wrar51b3.exe

WinRAR

The executable wrar51b3.exe has been detected as malware by 8 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from winrar-32.joydownload.com.
Product:
WinRAR

Version:
1.0.0.0

MD5:
ae83f9c001aa9a59783a1247a6cfdab8

SHA-1:
a9bd8692a859eb0c59434e1626064a42444efcf8

SHA-256:
752124149d3610dc5405e4b71c95e8a4eb1dc2701c89909f10d7668a535c5f14

Scanner detections:
8 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/18/2024 10:53:07 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160518-2

AVG
Win32/Sality
2015.0.4568

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Norman
Win32.Sality.3
28.05.2016 15:32:18

VIPRE Antivirus
Threat.4721115
50170

File size:
572.5 KB (586,200 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\wrar51b3.exe

File PE Metadata
Compilation timestamp:
5/20/2013 6:52:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:hQKEc7Y9XyIE5BL4r+ITBdMnRtMcijYBQR1yrkI61m:iKEkY65r4rMR3BQR1kkIt

Entry address:
0x331F

Entry point:
60, 0F, AF, F0, 88, F2, 0F, BA, E3, C1, D2, DE, 0F, AF, F2, 8B, FE, 0F, AC, F1, 55, 2B, FF, F6, C1, 01, 0F, C0, EC, C7, C3, D8, 8B, 3B, 82, 0F, BE, C3, 87, D0, 69, DE, D7, 33, 92, E1, 81, C7, C6, FE, FF, FF, 88, E6, D0, CB, 81, C7, 3B, 01, 00, 00, 0F, B3, CE, 3B, F3, 72, 07, B2, 04, 0F, AD, D1, B6, 2E, 0F, AB, F2, 0F, AF, E8, 86, F3, 81, FF, E4, 01, 00, 00, 0F, 8C, B7, FF, FF, FF, 69, C1, 40, 53, 9A, 47, 0F, AF, C3, 0F, BF, DE, 8D, 0D, E3, D1, EF, 0D, 0D, 80, 7F, 51, E3, E8, 00, 00, 00, 00, 86, D1, 0F, CB...
 
[+]

Code size:
24 KB (24,576 bytes)

The file wrar51b3.exe has been seen being distributed by the following URL.

Remove wrar51b3.exe - Powered by Reason Core Security