fnaf_world_demo.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from d-cdn.gamejolt.net and multiple other hosts.
MD5:
dd05c53fd9c6acf7912ff381349eeb8c

SHA-1:
575aa83d26d03b6c015d9386acc3ce6f3ed04315

SHA-256:
daeeacc01f324705f208f7940fcf86bfebfa26e3139f2d9638b5644d3b94c523

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 11:22:05 PM UTC  (a few moments ago)

File size:
224.9 MB (235,794,510 bytes)

Copyright:
2016 Scott Cawthon

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\fnaf_world_demo.exe

File PE Metadata
Compilation timestamp:
5/25/2015 2:59:44 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6291456:owpfOf0VFXRrLjg89vw/4l8/d5EpItg2kXnF3UPbKc2V51qHjnk:owpWf0HRrLjg8hw/4uwpI0XF329I51qo

Entry address:
0x6F7C6

Entry point:
E8, D9, 6F, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 70, 29, 4A, 00, E8, B4, 1A, 00, 00, E8, DD, 1E, 00, 00, 0F, B7, F0, 6A, 02, E8, 6C, 6F, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 62, 19, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.9986  (probably packed)

Code size:
528 KB (540,672 bytes)

The file fnaf_world_demo.exe has been seen being distributed by the following 12 URLs.

https://d-cdn.gamejolt.net/data/games/1/11/120761/protected-files-cdn/.../FNaF_World_DEMO.exe

http://s6832.chomikuj.pl/File.aspx?e=bp4_C0cX98o74C0QGARQy5_J-zVDD4vmXULjUVjt3-JWQj7GXSFnMovAND0dq2aRpkmYUQgk7PiLfHwRT3ggifUfKbwc3brwI4MO9QdfNjPyNES8KMRluBjtC9-HlbNzDB5WPX6EQaL4lsq2H2EcjmGJZFYnpdvFWQDj1BXIcRRfpdVr0G--TBWRvSQ7oA-hIym2AZi2SBS_ogKY2rSnRitXlV_81wgCtBvh24GboiiNeh_CT8odzdZXvIMgkf0gLKMhCFWUdPzkpTz78L4ZURAY85wCoPEvdIn51Qj572Cq3RwqhwEgWcDsOQsf6Ocfds1ZWbQGx_aGiFI3BAESqx8o-fDUQzuHmtNCUg1FJB6X15M4oVK2FAoF-DVM1IM_Fh2T7X8soBHqHMFZfk2YLg&pv=2

http://www.bytesendclear.com/WVl6OTRQWFJCWkRFNGFsWmhiV0Z1UlZWYU1rVnFhVU51UjBRMlRHcE5SRUZ3WlNVeVJtUjNOemg1YkRBd2VIZDFZeVV6UkNaalBXWk1kRkpRZHpSVGNFMTVWMjB6VFRZMlNXd2xNa1pqTjFORmJUSmlWVzUxYlhSak9XSnhSRkIyV1VZeFRITTBVVVpHZVRNMGNqVTBWRmxFUWpaS1drMVBRbTVLZFVWdE1GUkhTV052Wkc1aWIzTmtPRzFNYjNSUlJHNUpiVkpXVERaUE1XRjJSalk1YURCeE1WVjFjbEpEVlRCT0pUSkdjemw2SlRKR1VIRnhNRWRyWkdnNVNFSmtkblJVYTJoTFlVRlhjVEZ4ZUVrbE1rWkpkazVCSlRORUpUTkVKbVU5TVNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm1acGJHVnpMV1J2ZDI1c2IyRmtMbkJ2Y21Ga2JtbHJaRzluY25rdWNHd2xNbVpIY25sSlVtOTZjbmwzYTJFbE1tWlRkSEpoZEdWbmFXTjZibVVsTW1aR1RtRkdWMjl5YkdSRVpXMXZKVEptUms1aFJsOVhiM0pzWkY5RVJVMVBMbVY0WlNaa2IzZHViRzloWkVGelBVWk9ZVVlyVjI5eWJHUXJSR1Z0Ynk1bGVHVT0=

http://www.bytesendclear.com/aHZaGfUb1ysWZQqvMN80ZpcxzVfxF KdvkHnUosgNXG982rB etbfLY0pMTcz SmlaPqu7E66S2I9MIz3M90nNh_4lBurzUyCROSKvIxBucPC7vQju86 iaIW09H6YFcd9aRbWcr5WaIBBrJeHxPQIw7ShxvyczwBGJ1TvLdJEJ_XPET4n2N1aJctguYN04c8HQGscL770UNUzT94 M8NNUB_JML49dw4XqzyoQaeyX1tBKDVJY2g5L8zni_8x2C oqmtea5oTgrWROZDSbiChypM8q0giEYJPIRNxW8Yw7aisqCGnsR74FBChWBEJvg6YmNaQhOM 2PXqJLjBLiViAjQRjl6xGhxPf143eILlWskILllZe8oaM5eIjZ9Klbyz32xatWKJQggVK9v6EV4nuMM12ujuI_kWt0hL0keNhFxbMU2weVMSX0lX3XUu4blbgrxnsMqpGY4NyFa1hFvW 5lR0wrweW7WBEFVnE9N_5XcLkr4LJTeGJbWeFjkutsCxlesztCzhkpnSYLyfgbFeqIncx7e1zAzJkB9zKHtc0SfCags_Ion7M3M8RUZ61Q8NvWTeCtuI9YyFBj 3XmlSJvRc 5SFHNP6zQGIYLcElUpAK_8s=-G2EAAGR1Tqq1xgzwGA9EjnHgcNO1yGID6UaDhyx8XbUpmoBtjEQmdjOsy56VczeUS7N_sI4o9k9Fy79_z5BhvNa5qqYr_rlC7mX8yEFoNS1SQieUOR qtwI=-E

temp:FNaF_World_DEMO.exe

Scan fnaf_world_demo.exe - Powered by Reason Core Security