lewl.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from download1495.mediafire.com and multiple other hosts.
MD5:
ed9dcaf874b687402393966177e86429

SHA-1:
a3655251da01cea912f562bcce66f616dba040e8

SHA-256:
7100fc6ce4edb53db52240af60f4a731b5fa8b011eee7666f27146f27c102fb2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 3:02:24 PM UTC  (today)

File size:
257.9 MB (270,462,565 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\lewl.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6291456:/YSRYNVXeJ/x5BFDz6pJ6dFA6qAMTuiZFLAHcGrXrke4XTwO79t:/YSRGeJ/xpDVA6qdt6qx7

Entry address:
0x30DE

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 27, 7A, 00, E8, F1, 2B, 00, 00, A3, A4, 26, 7A, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 68, DC, 79, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, A0, 1E, 7A, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 80, 7A, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file lewl.exe has been seen being distributed by the following 46 URLs.

http://download1495.mediafire.com/c5nire9qqpgg/.../lewl.exe

http://download1116.mediafire.com/rs0di40z8a2g/.../lewl.exe

http://download1993.mediafire.com/7i9jlr9j1rhg/.../lewl.exe

http://download1993.mediafire.com/qyfhhv55pq5g/.../lewl.exe

http://download2205.mediafire.com/isk8jb594t0g/.../lewl.exe

http://download1495.mediafire.com/egzllwc8cfcg/.../lewl.exe

http://download1495.mediafire.com/o249nnzn26zg/.../lewl.exe

http://download1444.mediafire.com/boy7vjxqgy6g/.../lewl.exe

http://download2205.mediafire.com/bh9ul5ebye4g/.../lewl.exe

http://download1126.mediafire.com/vq5r04fiwsvg/.../lewl.exe

http://download1464.mediafire.com/d2ph0p55t8dg/.../lewl.exe

http://download1271.mediafire.com/95fl9gbrbtpg/.../lewl.exe

http://download1495.mediafire.com/l1rtb4osb16g/.../lewl.exe

http://download1495.mediafire.com/d75v5ch4gawg/.../lewl.exe

http://download1495.mediafire.com/w8ca6suhnceg/.../lewl.exe

http://download1318.mediafire.com/g7gp66g8q0tg/.../lewl.exe

http://download1495.mediafire.com/1untb07iogfg/.../lewl.exe

http://download1495.mediafire.com/hlpefjtvhzhg/.../lewl.exe

http://download933.mediafire.com/c1q16f03fcxg/.../lewl.exe

http://download1495.mediafire.com/g8x3wjcyv3kg/.../lewl.exe

http://download1495.mediafire.com/og54b38n9arg/.../lewl.exe

http://download1271.mediafire.com/08ts4bmegrug/.../lewl.exe

http://download2205.mediafire.com/y34tdqlqz40g/.../lewl.exe

http://download2205.mediafire.com/4v822kn1nh1g/.../lewl.exe

Latest 30 of 46 download URLs

Scan lewl.exe - Powered by Reason Core Security