57b94adc_stp.exe

Free Video Editor

OOO Vympel

This is a self-extracting archive and installer. The file has been seen being downloaded from www.vaultsfactorycentral.com and multiple other hosts.
Publisher:
Digital Wave Ltd   (signed by OOO Vympel)

Product:
Free Video Editor

Description:
Free Video Editor Setup

Version:
1.4.48.620

MD5:
f4750e8abe789d5868c8f53f0d8c75e1

SHA-1:
7fc6a91e827ec536492fc4c5fe8df42532c4af70

SHA-256:
f367448430e4b6483566a4e0aafdf9a7c9870432759458683e7f7c984b12b373

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/24/2024 4:58:32 PM UTC  (today)

File size:
26.7 MB (27,951,560 bytes)

Product version:
1.4.48.620

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\57b94adc_stp.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/13/2016 3:00:00 AM

Valid to:
5/14/2017 2:59:59 AM

Subject:
CN=OOO Vympel, O=OOO Vympel, STREET="Krasnoselskaya, 11b", L=Nizhny Novgorod, S=Nizhny Novgorod Oblast, PostalCode=603022, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E1BF6A1CF62A73022BF732C0792B0D54

File PE Metadata
Compilation timestamp:
1/15/2016 11:22:50 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
786432:Z9XmuKkVufYEHFCBt2dR1ZTWEOm1Ae4Xr9X2sDk4:PjuwElCn2dU9SAe4XFw4

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 34, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 1E, D8, FF, FF, E8, 6D, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 33, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 54, 86...
 
[+]

Entropy:
7.9990

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file 57b94adc_stp.exe has been seen being distributed by the following 15 URLs.

http://www.vaultsfactorycentral.com/c?x=ZOG1Ush1B57zPdRiAynJuzXSjN7R59d97TfgFHcuqqM=&c=2jH4TaUg9SaFNR3PgGcqhYM8KWwaxLsXZJTmyaFKfqfcPzfASVNiP2270UyfFyI8N3KVN9RS1LgtsymillRLlz6o9oftpzYybhkuYaY8 8Ro2JvHgEw4JH/aAjoTc/76&downloadAs=FreeVideoEditor_1.4.47.617_s.exe&fallback_url=http://.../FreeVideoEditor.exe

http://www.vaultsfactorycentral.com/2N96MwypeRGoaCT3MTE dTj_lgNryPLY_gYwuAIjI3HOA7gnz0nCt98OBbzTXImm26mo0irIvlhOTzRnilVXmdyxxCf7nITKYhqreVs_EJkd0UYr02Evg1UkmZyA1Hcs9yPJwKIdDUDIsVZ0JWt0p1Tkv3JEFpxHJffPjUXb9fcZnbo9QQCr36Eu1VqRcQPgKt_c9 ij2udjahfVwy1e1CPoJBCMpjU_DkP5Yw5VIFxURp3mnEwyrb6Pzq2ZhRP l_HIc_LaG6HK3_XDUQG0qEbiUGRx9JVErr EjyfImVDbhPFlcTbqWNTUVwF SJYZT3oClrThjA8_JURYEB3HmQGJixJhTJ_Z3DyVGndrl_OTWfkG0wFJKqLhRmXcDFdwhwFcwPm1TUfzWa8j1YmEPDEj3BFv_w==-Gy0AAERPFttLI0Sh INkMzPgkAP2f5mkAVhNdR4oN55K8IhoSXn1kYIeY20P9AI=

http://www.vaultsfactorycentral.com/6Fzk3sO8A2QqJLYfSS07qtuxXURxRszNZfOp8iD1WAASQNd2CtoqE3QYRi6pUugn2O4_EFfKazDOnQ6ngMPhaUnigZzDWpURm5Snac76iXi1l2dR5gXqquFoL2Vp_FATJdBqv1itSm3BlR5 IxiAWhv mer0zF9C5j2eDME oDsv7Y2SjHn2SBeYMSWjR9sZY8ju4njCSHvTxei8NgoPOODeMUDs0WgjOF_G3lf13RDRou5jSqUrEpdd ot_3EhBU2qJbG h9pheVgSPjGE5q9GPlYi9U lIRxDyfDClfrJPiwrySthd7LVCOZx69dAhqJT HWSlW9GpCRxZjFcM3J2yQC4hUJlzKbGtp1yL3_QTnwccV8QpwA585yEL 1srUpOoksBgRiztXSv1O7Nq2Max6h3m8ymHjpybtgKDRHvzT5 bozw=-Gy0AAERPFttLI0Sh INkMzPgkAP2f5mkAVhNdR4oN55K8IhoSXn1kYIeY20P9AI=

Scan 57b94adc_stp.exe - Powered by Reason Core Security