ps loader_dzarion_v2.exe

DzArionLoader.exe

Dz4EvEr

This is a setup program which is used to install the application. The file has been seen being downloaded from docviewer.yandex.ua.
Publisher:
Dz4EvEr

Product:
DzArionLoader.exe

Description:
Dz Arion Loader Application

Version:
1,00

MD5:
9292abef781b6c6a7e445ee9b8c19e76

SHA-1:
985aa7d78e9d6d97948e0de86e810932395666b9

SHA-256:
275563642915a6b70016911f458e25e78c8f98b75de8bd82d79714d7b2079d19

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
6/16/2024 10:20:56 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.4959

File size:
594 KB (608,251 bytes)

Product version:
1,00

Copyright:
Copyright© Dz4EvEr Jul 2007

Trademarks:
Dz4EvEr is a registered trademark of AEK_KM2004@YAHOO.FR

Original file name:
DzArionLoader.exe

File type:
Executable application (Win32 EXE)

Language:
Arabic (Algeria)

Common path:
C:\users\{user}\downloads\ps loader_dzarion_v2\ps loader_dzarion_v2.exe

File PE Metadata
Compilation timestamp:
7/31/2007 2:12:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:sj0lGq2S8GkDLmPVlaeXPOiEz3nPwkzDpFiIwgJ5n:bAbGkDLmPBFEz3nVFFiIjJ5n

Entry address:
0x121000

Entry point:
60, 50, E8, 01, 00, 00, 00, 7E, 83, C4, 04, 58, 66, 81, D8, 9C, 26, F8, 76, 01, 43, 72, 03, 73, 01, E9, 81, E9, 5B, 06, 52, 67, E8, 01, 00, 00, 00, 7C, 83, 04, 24, 06, C3, C1, E8, 8F, E8, 01, 00, 00, 00, 7E, 83, C4, 04, 87, C8, 50, E8, 01, 00, 00, 00, 7B, 83, C4, 04, 58, FC, E8, 01, 00, 00, 00, 7E, 83, C4, 04, 0F, 88, 04, 00, 00, 00, 66, BD, F6, 11, BB, 6B, 11, 52, 00, 50, E8, 01, 00, 00, 00, 78, 83, C4, 04, 58, F9, 68, 0D, C1, 90, 96, 0F, 84, 02, 00, 00, 00, 85, D5, 5F, E8, 01, 00, 00, 00, EB, 83, 04, 24...
 
[+]

Code size:
1.3 MB (1,310,720 bytes)

The file ps loader_dzarion_v2.exe has been seen being distributed by the following URL.

Scan ps loader_dzarion_v2.exe - Powered by Reason Core Security