firewatch_pl.exe

Firewatch

www.grajpopolsku.pl

This is a setup program which is used to install the application. The file has been seen being downloaded from www.bytesendclear.com and multiple other hosts.
Publisher:
www.grajpopolsku.pl

Product:
Firewatch

Version:
1.0

MD5:
fb7cff71833d0d04bcad9f991c5cb82f

SHA-1:
b82c23b0b874dc5b78ad23447776317eed6cd2d0

SHA-256:
05bc2c9f200a19a2281ba4360531a02c1bda8e4273c004770baa32a9b2667dd9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/26/2024 12:55:13 AM UTC  (today)

File size:
33.1 MB (34,723,268 bytes)

Product version:
1.0

Copyright:
www.grajpopolsku.pl

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
7/16/2015 3:24:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
786432:f+oW2GDrBSsUuEOSTsdw+xouKM0g+QQVC2ohaKcEImmno2Mt6/5gLlKu:fzW2GDrBdUuJdw+1KM0g12oIjTno3RKu

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 34, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 1E, D8, FF, FF, E8, 6D, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 33, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 54, 86...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file firewatch_pl.exe has been seen being distributed by the following 4 URLs.

http://www.bytesendclear.com/lGAizRjmI0PgZTbdnulv8bbgvLKn6UWM8BlTECzRf8LcJSiztV4smFvMsNiAaJXYx72creO2UaGjgaeONtvsx0xia6SrAnwUTXeowyTrnWxRZXU9GtYB3mSnQmUDdVO8n6ftZbk65JEVN447FeAz392xW0Wbrm uFYiIPBK9CKZ_pVAMkQYkNQMT4_1mhMvFLAd tc3Xz_Ao0UKLiBVuYYOAiVpa0Y_hkVIXzbvESp4qyyLDEwKs1zkIq4F6BHjQviZAkQB3IXkYUIbHvAr7n9gDbhsxq19pxEFF3NGrXaXOqaxqobVlivEGyAMOSZO847ECmM3qr7GO3I1x9S0Qfh2WAuZTQ6wS_fkHI2Fxl2H0lh3yuSwjLlZY0HyUGq3JBr0oGZZDvWJERGRPFZsJB_QsrO9XNtJJgMNSu K1U6qeMXWvT7QRnZCwygCuEbMbHXPDVodIyD 3Q_gtaLzPI_7G3YR2YPq28jrP2c3FcYjUB7GsBal4Kqr9F1T f2Rx1ShvzFc_QXwzBy2UFfbn0XN Mxft030 U3PUNbLBvmaccWe57P M2yVfMDBm5LFzVjUw8spC-G18AAGTYtrmE86z ZFgBDjlw K4ZRBSIBxtjfMcRO_nGLEqie4B12QmPxvFF7R9YPcz2rxiXf_8eR Dsr0DYL6IhmRE7TM0ucqavadTXQLwC

http://www.bytesendclear.com/OTn6_aFE5hDg8_FnVr6ZFuG_JYHr fQNqMseC6Q8zHeFG_mE_F6xhXNABba086_FtzB1zZ2k odhSL9tzYITwIP xDtUMtWhPmc2wdUMoTrMxpg3XLrpxtNUmr at_y84dBghA0mqgFreaVkMkYCA0nlMyr9smvMeIXd7dSN8x5I544qImd8_FBAL8maV8A_70sIYg97MXGvPU93lUQ5ZEyQRoHlnXJBGOiRSEaiJUUnwlqSLjizNWOlK6rnhbRCJ4d6UjHDx2da168VGODGt4DQHxkVMaRB0AKTKwqKRvJVDIQxGtlh49uR7dEp0MAstb5hp3H5WTc8zRmR4saKJHKzWrGUPteBJQ5zbQm01HeofhjZ8ToVr9iHjzUNPaxddj1ybDQRSnx22y__Sz71jgLtHhuE6xeF7SSGsD tW5 aVoMT8W0joLtXNzNeXxA3R00_UPVlSSfzsGWBGpxXF H15eGWeKuZZNEDrqvIML6JdrH9HhgRDr0GvcYXu2nKdhxmx1BS3_JWkZKG8rN1wVFTm9D7isW9aGKCfy3UO KoQdJ5Fwe6b raq9I69_FGtBMmO3_t-G18AAGTYtrmE86z ZFgBDjlw K4ZRBSIBxtjfMcRO_nGLEqie4B12QmPxvFF7R9YPcz2rxiXf_8eR Dsr0DYL6IhmRE7TM0ucqavadTXQLwC

http://s5863.chomikuj.pl/File.aspx?e=DuPJy53Wlc3sfgrhYL2E_-ah2RW7lONusKrcsFnTJaAx22TGpSj3JfbtvANA-9l4Ucz1LH7hnAj1zpWeRqJRX_A5xfKI0ydWiqSMoFfkIOTSrjjGmkDfGe9JqGlANfu5UOanx3PoJPqxfDklvElFzotBYAeIdaKay6VcvusBTfY&pv=2

Scan firewatch_pl.exe - Powered by Reason Core Security