228_swkotor.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from rusifik.ru.
MD5:
6426c7a3f0286d50e951086c7aef5385

SHA-1:
008851afaafe021c12e6f1a00f68a4b12e4e643b

SHA-256:
4faa3310bbd0a2b27455e13c892bdd909224d411799a6375e748ecc5acccca4c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 12:54:21 PM UTC  (today)

File size:
3.4 MB (3,552,506 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\228_swkotor.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
98304:1LZHLjeDTTFUZoYQmxId2SNEr4j2cuhsJ06eZ/cNJ9N:11Mtc7MiM27A99N

Entry point:
52, 61, 72, 21, 1A, 07, 00, CF, 90, 73, 00, 00, 0D, 00, 00, 00, 00, 00, 00, 00, C4, 5C, 74, 20, 80, 2F, 00, B0, 34, 36, 00, B0, 34, 36, 00, 02, 79, 10, 35, C2, 23, B4, 2C, 48, 14, 30, 0F, 00, 20, 00, 00, 00, 32, 32, 38, 5F, 73, 77, 6B, 6F, 74, 6F, 72, 2E, 65, 78, 65, 4D, 5A, 50, 00, 02, 00, 00, 00, 04, 00, 0F, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 1A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

The file 228_swkotor.exe has been seen being distributed by the following URL.

Scan 228_swkotor.exe - Powered by Reason Core Security