flash_upgrade.exe

github

This is a setup program which is used to install the application. The file has been seen being downloaded from cdnfiles.4shared.com and multiple other hosts.
Publisher:
github  (signed and verified)

Description:
Svit Campor dagma

Version:
1.4.0.50

MD5:
5a382101d4bd093368f5fbf84100ad31

SHA-1:
5b2cc151d81b1c41e8167ac5938faa39d5241881

SHA-256:
c0df6d446f43f9aaa92358aab970ced838ba000daa86e8e224657c8dca482656

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 4:36:03 PM UTC  (today)

File size:
745.4 KB (763,336 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flash_upgrade.exe

Digital Signature
Signed by:

Authority:
github

Valid from:
5/27/2016 12:53:57 PM

Valid to:
5/28/2017 12:53:57 PM

Subject:
CN=www.github.com, O=github, L=Sokar, S=Vadir, C=AO

Issuer:
CN=www.github.com, O=github, L=Sokar, S=Vadir, C=AO

Serial number:
00C61014451A061296

File PE Metadata
Compilation timestamp:
6/1/2016 4:11:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:PaVo8cxvoloPIUyB6HRpUKW52/dOO5wcQQU4wKx9+G:PwvmvTI7BAMV20gq47D

Entry address:
0xA279E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 70, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
642 KB (657,408 bytes)

The file flash_upgrade.exe has been seen being distributed by the following 2 URLs.

Scan flash_upgrade.exe - Powered by Reason Core Security