Suspicious 86% windows Download

PCSX2Team.PCSX2

Unsigned, checksum mismatch, high entropy

Innoextract found setup loader checksum mismatchInnoextract found unexpected setup loader revision

Evidence

English function-word token "this" 0x0–0xc0
0x04d5a50000200000004000f00ffff0000MZP.............
0x10b80000000000000040001a0000000000........@.......
0x2000000000000000000000000000000000................
0x3000000000000000000000000000010000................
0x40ba10000e1fb409cd21b8014ccd219090........!..L.!..
0x50546869732070726f6772616d206d7573This program mus
0x60742062652072756e20756e6465722057t be run under W
⋯6 more rows
Borland locales registry key 0xb73c–0xb80c
⋯3 more rows
0xb76c4c006f00630061006c00650073000000L.o.c.a.l.e.s...
0xb77c53006f00660074007700610072006500S.o.f.t.w.a.r.e.
0xb78c5c0042006f0072006c0061006e006400\.B.o.r.l.a.n.d.
0xb79c5c004c006f00630061006c0065007300\.L.o.c.a.l.e.s.
⋯7 more rows
Disk free space query 0x2332f–0x233ef
⋯3 more rows
0x2335f002e0064006c006c0000000000470065...d.l.l.....G.e
0x2336f0074004400690073006b004600720065.t.D.i.s.k.F.r.e
0x2337f00650053007000610063006500450078.e.S.p.a.c.e.E.x
⋯7 more rows
ChaCha20 cipher algorithm reference 0x25da8–0x25e68
⋯3 more rows
0x25dd8490073005c0069007300730072006300I.s.\.i.s.s.r.c.
0x25de82d006200750069006c0064005c004300-.b.u.i.l.d.\.C.
0x25df86f006d0070006f006e0065006e007400o.m.p.o.n.e.n.t.
⋯7 more rows
GetMethods member-name token 0x3ca94–0x3cb54
⋯3 more rows
0x3cac4414e616d650200020035009c4f45000aAName....5..OE..
0x3cad44765744d6574686f6473030030234400GetMethods..0#D.
0x3cae408000208dcd9430000000453656c6602......C....Self.
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.