frim_win_int.exe

frim_win

MoCo Media

This is a setup program which is used to install the application. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
MoCo Media  (signed and verified)

Product:
frim_win

Description:
Frim application

Version:
1, 0, 0, 1

MD5:
3817c4d7831ee7a4ea33472c18ac8878

SHA-1:
2339a2d46cd4114dbfda181a938df9b699426fea

SHA-256:
f20e7eea0d2dcb24dab99ba75b52ce1359929fd99e2614035f75b44dee9882cb

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 1:16:18 PM UTC  (today)

File size:
338.8 KB (346,968 bytes)

Product version:
1, 0, 0, 1

Copyright:
MoCo Media 2014

Original file name:
frim_win.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\frim_win_int.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/28/2012 2:00:00 AM

Valid to:
8/28/2014 1:59:59 AM

Subject:
CN=MoCo Media, OU=IT, O=MoCo Media, L=Ekaterinburg, S=Ekaterinburg, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
372F28A7FA989110D91F051A51F463AF

File PE Metadata
Compilation timestamp:
8/26/2014 2:27:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:PsJ9YYo9NQRML/kTUMdwy9ABEa3rz8cd5PND8dOKDeeI:UkY8NQR+cgMv9+Ea3Ucnl8cNz

Entry address:
0x2329E

Entry point:
55, 8B, EC, 6A, FF, 68, 10, BE, 43, 00, 68, 88, 7F, 42, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 9C, A1, 43, 00, 33, D2, 8A, D4, 89, 15, 14, 95, 6F, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 10, 95, 6F, 00, C1, E1, 08, 03, CA, 89, 0D, 0C, 95, 6F, 00, C1, E8, 10, A3, 08, 95, 6F, 00, 6A, 01, E8, 44, 30, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 0E, 2A, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
228 KB (233,472 bytes)

The file frim_win_int.exe has been seen being distributed by the following 12 URLs.

https://dw.uptodown.com/dwn/m1PymF5aRAM8AS7cbJdp7SfIH9YHFqL1GYds1JxpPYlJ3gaDW-yvocHKhdWIQN9LJ4VsLiLcyrorQrmBHQQ3OLqQBnoHHAqGkbUr1ptwa_vdWw9Os7sro_Q6xNDS3mua/ZjDDyKaj2q6X-_AsC6OowW21c-m1q0DsWs0pzdj2gD4KlmyqCuCxJibjQOvMsJLNtQRN7God4TlZzecoEnRNiOmd1gKabNtvM912r8pSTivLeME5a2o3-79ygHUPAQF0/fQy5TkSw_j2uIOOUeEt3cIDGKmgbfoxhwU4uIuaohGLnJwB9CizTRItFccDdmli3VIFJEeyRjTJtoVqz1C7T3aeKotXIqJzG0pJv8zqd_LZcXwgxzxL-2odOvuuAlNtE/.../

http://dw.uptodown.com/dwn/rgXv3u4JrJXn4L0uYH1_iDjOoTX9mctfkMwnHeefmmcfyHUBTq4WMK3Uqje2J1k6KPW4dQVm_XuG0KcGIoGWrBjABMi0XtBcXwjrBzhE7rtRZ_s7A8bJMOFcvGI1n-BJ/4e-BWvPUoVcILKC3sWWqEOaSbm4g-NnoFWUR-yTCYGS9_BxaGyt7GOZEByRhMGP8_4LUVU6_QiK1D-N58hei2knOf0gYqlRC8DzyJOkGUIB-DvVWrjIKzQeYFkm-7BIx/.../

https://dw.uptodown.com/dwn/IBmRxtni8S_dFpQGeqCX6sqC4suuwRNpMmeEUHhSkmP42ux9S-nFJtjAfmW8ZmHvItGnh1crurTiNeQ8si9dkcJcL9OIURZhDgl2fb1TB8yX-1dEmB_jCMgMblWyzO4C/D5_XNGJ8FgEui6-67RjJPE0WSBoRX-KdW3UGM6mhyvp_GinSWNCt2-3GRI6eeupDZfqEksF1ZF0MHi9OLh2qyPkXqIBhOPKEDfVc3Tewf6dSZ5sjPyiKcbHCt_slwWvX/0sidLn-zOsuLf2jahR9pfcDsWt6V1_mTn3dipnfiW_ijGkG5_8UEhGaRbVICVeUkh_GDaO3qc_slp0sbfBHXng5lqFsI0xRfOu3Trf82sh8lWVSQTXXjrlUmtH8gu-NV/.../

http://dw.uptodown.com/dwn/muq7Q4AXtqrwar_K6SxUT0KlqFAyV43dP7UChSrNKQaBfuJuzbAelPdNiXeB4fEJCmWa1M7MRshBhzBn4PqqAjRIruATAN1mq6C9MY3DT3CwO-Z_CMdu_xOL-m3IQXbE/.../

https://dw.uptodown.com/dwn/SSeZOPWlNapnc_w3lzbnFi6VeiruJHyQ4lRnqo1JMnpu7keLWfJnIU4lCNy2969q6UmEjTJ2RWpyKUjhcOPitpSR-jSf-Q4_b55Nu-E27vMUO-9WOD2ONylL34Un4DcL/iQtKT0d7tgQQGOtgCUTzpsOy-tadDOLb5PRLdzMeQJy4OUdDXLHChG1R_5k0OI_6tHlluODLQyHKwbMkT7f3UnkXmuU2enqdaYgQyCofh7d3JargEfz34OoG5PsjEXpy/l7D4F98Z9uh2JfwvuhLUZxFl26EGY6cuMTcg7448RT9ouujA-5qYNVfwFT9f-fauD82GfJzyuaGp_g8cDoqrwLCbLn7Q01zMk1Ia3ThaGV4TAXHSDreCHXnhTmxnG_Dg/.../

http://dw.uptodown.com/dwn/wFdWVO22tpiv_as1CYF-Nd92t2PYCwslAEEh5IxYvxdLAGimhFSEYusaUrJf8TX4zr7lGdgypwa6nBsGWZssFKiJyZuquywbcwP6xyRQmphBsY6V3De5fSIY-PqhnSW5/1H49pfSRGj8Z6Ux2c-yKAXLUMtkzIacmuzsQcae2-9kwbI88CWr0Ll_KRQ6uKEbXCDDmFZTrUiRZCJ222ABafv7Y8QNhoCUGUbFRb_4p4PDV2avqOteEGsPH0uoL9jw8/AraAKIjWd_JcE4m5pyJyc0LID2Pil8dB1mzSjfEUCxkXFZ61nie7icJoOk_qT69KwSibtwUo7q1TuQ6EACw-EZqmvuRYzUuAXMAzjJzJfbuznSvIGpf7nMHg2KgCUGlB/.../

https://dw.uptodown.com/dwn/fT13oViwgxWsjmAXD_ZHc4PV_j7Qw7vnnK0M4qmya0cF33FulJLYgSUyHPg5j0T_45D9TAhWbtgBukmYOYh19Fncj3HHROQb-MRgyNCp3zoQxcYGcjlAuoJuO7Je1BQF/3YkwlyTzOPQt3DJHOk5rJfojLqm_iujf4nTr_6SgiCqf4YnRkRSQmIvdGwnWEq4o39rGITFLyTnjaIxCtbuKhS4oKtVl_dzjCxzjTlgsh5YyMQgoWuTOdwHIjZ8i3Uu9/Tp6RuoGbybJxHd6Cb_hVAmNx3Yv7ZABCjTW8NbzZo3Fm40-4HEAMiOGBgang6Djx_BwFXnU5po-xgHB8sEUXv_-BmoITJMhBE6nHjDBkZmvdNq7aRIjBhNnSIgRMuL1Z/.../

http://dw.uptodown.com/dwn/1W9p51KR90A9bkyH8BH67iAFk5i9PN4xpKii2igdFDsIessuDEyLWoQI7eYQh7JrJELQodBC1CgrDcHIjFRldT60TPBNmw8AnmRTMuaPFWQ5aET0Cr51Y01loBOi0LEN/raE8mVMHQleh-CBxXsuMlMkbB-SblDn5HRM_S_pdB6OoZAezpjTCBaFFssXGjyq2Z0rXnA02tSTw-rkSlJzqHauNRrV9_xIuGgGx9LQpqrE6OsiIYFmUc3ld5UDXH62p/.../

Scan frim_win_int.exe - Powered by Reason Core Security