exam.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from mail.yandex.by.
MD5:
6c79c5e51b88e655b8d98069fd21076a

SHA-1:
5201efa5ae1265584e1cac1a709cb12566d5762f

SHA-256:
757dee2953a09a426f3e4965228691057bb866c1562423b35a9bcbf55f516e6a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 2:32:45 AM UTC  (today)

File size:
508 KB (520,192 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\exam.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:DzfOtXCaSDWlAD57Kx4gf78GH2HKu4hxy8PAjI/:XfKy1VD3gf78GWKPhxUI

Entry address:
0x6B4A8

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, B8, 80, B2, 46, 00, E8, 82, B3, F9, FF, 8B, 35, 40, D2, 46, 00, 33, C0, 55, 68, 82, B6, 46, 00, 64, FF, 30, 64, 89, 20, A1, 00, D0, 46, 00, E8, 28, 95, F9, FF, BA, D0, ED, 46, 00, 33, C0, 8A, C3, E8, 1E, 74, F9, FF, 83, 3D, D0, ED, 46, 00, 00, 0F, 84, 86, 00, 00, 00, FE, CB, 74, 0A, FE, CB, 74, 27, FE, CB, 74, 44, EB, 63, 68, 98, B6, 46, 00, FF, 35, D0, ED, 46, 00, 68, A4, B6, 46, 00, A1, 00, D0, 46, 00, BA, 03, 00, 00, 00, E8, 60, 98, F9, FF, EB, 57, 68, B0, B6, 46, 00, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
426 KB (436,224 bytes)

The file exam.exe has been seen being distributed by the following URL.

Scan exam.exe - Powered by Reason Core Security