alawarenfarmfrenzy2.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from eq02.mirror.alawar.com.
MD5:
16619889512bc5ee970b1d9c33126fdb

SHA-1:
bfcc973a285f5de11752423c2b7e4a1920d8fd20

SHA-256:
727cae271730fb04f9910b996697901edd2ab494a052f839a39b70de4806dc18

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 10:49:35 PM UTC  (today)

File size:
35.4 MB (37,132,664 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\alawarenfarmfrenzy2.exe

File PE Metadata
Compilation timestamp:
4/10/2010 3:19:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:UgxjMTpE9E52eYxpT7gr/kO0xlv5ahOGHxE3tY4K:U2opEukR/y/e5awEE3tYV

Entry address:
0x354B

Entry point:
60, 1D, BD, 8A, 95, 44, B9, EA, 5C, 58, 3B, EB, 09, 89, E8, 43, 8D, 0D, 2E, 25, 46, FD, 8B, C1, 8D, 1D, 92, 3B, 41, E2, 84, CD, EB, 03, C6, C6, 64, 8D, 0D, FE, 25, 87, 8C, 8D, 3E, 81, FE, 72, DF, 00, 00, 72, 08, C7, C1, B9, 6E, D7, B8, 38, EE, 8A, F6, 8D, 07, EB, 0A, BB, D7, B0, 7D, B7, 0F, AF, F5, 09, D3, 8D, 35, FD, 32, 0F, C1, 2B, E8, EB, 04, 0F, AF, D8, F3, 8D, 15, 97, 1A, 10, 42, 0F, BE, F2, 0B, D0, 84, C2, BE, D1, A8, B5, 18, 81, FD, 58, 3A, 00, 00, 76, 06, C7, C7, 3D, CF, 40, 75, 20, E2, 8D, 35, E6...
 
[+]

Entropy:
7.9932  (probably packed)

Code size:
25 KB (25,600 bytes)

The file alawarenfarmfrenzy2.exe has been seen being distributed by the following URL.

Scan alawarenfarmfrenzy2.exe - Powered by Reason Core Security