clashfarmer_189_installer.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from secondary.clashfarmer.com.
MD5:
0527c5091ded60de166cccbbce46ecd4

SHA-1:
f746f16fe3e87ddde84ce8d3c29d63d3281eaf84

SHA-256:
da21292cba7e316122bd7d9782f8c139b7c673f0f80c7044282028d1231f9319

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 2:38:47 AM UTC  (today)

File size:
25.3 MB (26,520,224 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\clashfarmer_189_installer.exe

File PE Metadata
Compilation timestamp:
12/6/2009 7:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:oSH5GZNLLa/LklGA+SMlS8Xk5i0oP7afBVRUhHXxJiWRQ1uWDqe:oc5GZNLLa/fHBk80oP7mBAzqow

Entry address:
0x30FA

Entry point:
8B, FF, FE, C0, 0F, BE, C4, 89, D9, 11, DB, 8D, 05, 5A, 2F, 7C, C5, 3B, FB, 70, 08, 85, D1, 81, CA, 2E, 24, D8, D5, C7, C1, 90, A2, 6D, 1B, 86, DF, 76, 04, 01, C5, 8B, D8, E8, 00, 00, 00, 00, 86, F1, F6, C3, 68, 87, CA, 8B, F1, 87, E8, F6, C6, FA, 8D, 3D, B3, 1E, 16, C3, 13, EF, 03, DB, 0F, AF, EF, 81, EF, 16, 1B, 9E, 05, F7, C6, 2C, A5, 32, FF, 5B, EB, 02, 86, E5, C6, C6, 28, 69, F7, E6, BA, 90, ED, 0F, AF, C6, 8B, D0, F7, C1, 68, 68, 8A, 48, 0F, BE, CB, FF, C2, 2B, EF, 2B, FF, 24, 1B, 28, D5, 23, D6, 69...
 
[+]

Entropy:
7.9981  (probably packed)

Code size:
23.5 KB (24,064 bytes)

The file clashfarmer_189_installer.exe has been seen being distributed by the following URL.

Scan clashfarmer_189_installer.exe - Powered by Reason Core Security