eav_nt64_esl.exe

Win

Microsoft

This is a setup program which is used to install the application.
Publisher:
Microsoft

Product:
Win

Version:
1.00

MD5:
8675825b1c1e12d7f57920edd428e833

SHA-1:
a41879528116676099b2e16a83f9ce070ed1d779

SHA-256:
477d932469ed091704bc1fb3e522653a4c226e0d6b81aa155317593dc86adc03

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:23:07 PM UTC  (today)

File size:
91.1 MB (95,536,600 bytes)

Product version:
1.00

Original file name:
Win.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\eav_nt64_esl.exe

File PE Metadata
Compilation timestamp:
6/14/2011 2:01:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1572864:WUJlOVD1lmKurF7018vfwFu+7LG0r2omFgifJjsiPl9SXyuriKcsOaugNs7bj8YP:DqbmK2Q8vfw8+nXrauYgWcXy8fsoYP

Entry address:
0x3670

Entry point:
88, E0, 81, F5, 56, DD, 87, 70, 84, F3, 86, E3, 71, 06, 81, FF, 1C, 30, FD, 09, 85, C7, 8A, D4, 8D, 1D, 28, FE, 1F, D0, 0F, BE, FD, B8, 00, 00, 00, 00, 72, 04, 84, F4, 88, EF, 0B, C5, 0F, B7, F5, BA, BD, 34, 28, 14, 8D, 15, 87, 01, 08, E4, 03, C8, 81, FD, A1, C1, 9B, 42, 8B, DD, 8D, 3D, 8A, 75, C8, 8B, 0F, BF, FA, 80, F4, 40, FF, C3, 23, C9, E8, 9F, 00, 00, 00, 03, DE, 69, EE, E7, 45, 4A, 73, 11, C8, F7, C0, 4E, 6A, 88, 41, 8B, EE, 84, E1, 69, F3, F3, 6E, DD, 72, C6, C6, BA, F2, 69, D7, 4B, 9E, 24, 6F, 2B...
 
[+]

Entropy:
7.9724  (probably packed)

Code size:
172 KB (176,128 bytes)

The file eav_nt64_esl.exe has been seen being distributed by the following URL.

Scan eav_nt64_esl.exe - Powered by Reason Core Security