wrar520.exe

The executable wrar520.exe has been detected as malware by 12 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from freedownloadwinrar.net.
MD5:
220fd99914ca16d98d711def68dbc845

SHA-1:
766e75a03e875f02ec1ffe95a2b695fef9e2b9ce

SHA-256:
fbb6a3db24a7ea99f5284db5d131fe956f418b8d4f75705387d928d29757d325

Scanner detections:
12 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 12:59:13 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
5819428

avast!
Win32:Sality
160112-0

AVG
Win32/Sality
2015.0.4489

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.2626.0

Norman
Win32.Sality.3
11.01.2016 17:30:26

VIPRE Antivirus
Threat.4721115
46446

File size:
1.8 MB (1,837,832 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\wrar520.exe

File PE Metadata
Compilation timestamp:
12/2/2014 3:37:41 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:tUktLTtVVsHahDtpfZRJBnaEONoqpn6eyU0iqfb71RG:tTtLTt0Ha7pxRHaEONoqpn69U0b31M

Entry address:
0x1D00B

Entry point:
86, C9, 0F, BF, F9, 57, 68, 8E, C4, FB, 00, 88, F1, 49, F7, C3, 2E, 32, 7C, 81, 45, 57, C6, C4, A4, 22, DE, 69, F9, 7E, 0F, DA, 8B, 84, C3, 4F, C6, C5, 6A, F6, C5, DB, E8, 7D, 00, 00, 00, 01, EE, 0F, AF, DA, 84, E7, BF, 11, 1C, A6, DB, 85, DF, 80, D8, EA, 80, CB, 03, FE, C4, 89, D8, C6, C7, B6, 81, FF, 43, E5, 00, 00, 76, 03, 48, 86, C0, 8D, 07, 50, 5B, F2, 0F, AF, C3, 0F, AF, C0, 8B, F3, 80, E0, E7, 34, FC, F2, B8, 70, 8F, 27, 6C, 8D, 1D, 75, A5, CF, B1, 8B, CE, 4B, 85, D9, 86, E3, 86, C0, 8D, 39, F6, C3...
 
[+]

Entropy:
7.9555  (probably packed)

Code size:
160 KB (163,840 bytes)

The file wrar520.exe has been seen being distributed by the following URL.

Remove wrar520.exe - Powered by Reason Core Security