frod-fx.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from docviewer.yandex.com and multiple other hosts.
MD5:
548bea0f2cdcdeafac8a245f44115907

SHA-1:
1f1d5ad6a060105e3161d609c2d2686d5a9f3d21

SHA-256:
c4fbda4f228e0af24b0aa79da43cf11c2731f3cd48e6f20c6d96e2fce0e926be

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 7:11:04 PM UTC  (today)

File size:
362.5 KB (371,200 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\frod-fx.exe

File PE Metadata
Compilation timestamp:
6/20/1992 3:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:hIWiuTHlffy8uBnP7l71h7m3BP8shnk3/0d8UY9jGcFYAtgjrJzBLgl:YuTFffy8u1PpKP7pk3nX5tgfJxG

Entry address:
0x4CE68

Entry point:
55, 8B, EC, 83, C4, E4, 53, 33, C0, 89, 45, E4, 89, 45, E8, 89, 45, EC, B8, 88, CC, 44, 00, E8, 44, 8D, FB, FF, 33, C0, 55, 68, 27, CF, 44, 00, 64, FF, 30, 64, 89, 20, B3, 41, 8D, 45, EC, 8B, D3, E8, 5A, 71, FB, FF, 8D, 45, EC, BA, 3C, CF, 44, 00, E8, 2D, 72, FB, FF, 8B, 45, EC, E8, 1D, 74, FB, FF, 50, E8, AF, 8F, FB, FF, 83, F8, 01, 74, 48, 8D, 45, E8, 8B, D3, E8, 30, 71, FB, FF, 8D, 45, E8, BA, 3C, CF, 44, 00, E8, 03, 72, FB, FF, 8B, 45, E8, E8, F3, 73, FB, FF, 50, E8, 85, 8F, FB, FF, 85, C0, 74, 1F, 8D...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
304 KB (311,296 bytes)

The file frod-fx.exe has been seen being distributed by the following 8 URLs.

https://docviewer.yandex.com/source?id=3dfm-hfsg7sne5p72kbrm5uyi9ly57ymvu2cjlzaoh7ip3qq8or0rvm82u2hjvs6kngfzjr78ooictlb9swkul8vcj6yw4em7mrwiaov&archive-path=//frod-fx.exe&ts=15227fe49b2&token=aKBxz5QnS8f61qiD4OL8mQ==&name=frod-fx.rar

https://docviewer.yandex.ru/source?id=3dfg-9fugnp43fiq3beonbj7ob2meinxaaqcklh3ifqafpwqux1nm5qzi585i7tdqvqbs8ztm6et657xyf2ugm6568jv556ztx3r875y&archive-path=//.../FkBAds60IkWCsg==&name=frod-fx.rar

https://docviewer.yandex.com/source?id=3dfm-hfsg7sne5p72kbrm5uyi9ly57ymvu2cjlzaoh7ip3qq8or0rvm82u2hjvs6kngfzjr78ooictlb9swkul8vcj6yw4em7mrwiaov&archive-path=//frod-fx.exe&ts=157bf6f8e97&token=OHzZ824DQR76mPZkggX1Ug==&name=frod-fx.rar

http://procsgame.ru/.../download.php?id=434

https://docviewer.yandex.com/source?id=3dfg-9fugnp43fiq3beonbj7ob2meinxaaqcklh3ifqafpwqux1nm5qzi585i7tdqvqbs8ztm6et657xyf2ugm6568jv556ztx3r875y&archive-path=//frod-fx.exe&ts=156a8fc6991&token=1J0Gr4K3TUm4PjRw7AVS4A==&name=frod-fx.rar

Scan frod-fx.exe - Powered by Reason Core Security