lordsofthefallen-ru-languagechanger-v2.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from fra-7m15-stor02.uploaded.net and multiple other hosts.
Version:
0.0.0.0

MD5:
bb883d7a5f8f4abbd40d3d143cfd937f

SHA-1:
67f626f525fa4f79b258018a1261623510ea65ae

SHA-256:
8d2d8e005a6422106d38ff74f438cde6b7e59509a12b4488472031032b42264e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2025 4:25:36 AM UTC  (today)

File size:
10.5 KB (10,752 bytes)

Product version:
0.0.0.0

Original file name:
tst.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\lordsofthefallen-ru-languagechanger-v2.exe

File PE Metadata
Compilation timestamp:
10/29/2014 4:02:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
96:Ou/stLGINf46rYgdXWTzdr28yi2A5AQQi7jSmlNL+7xq8WPFCR+3ERebRlmn5y8h:itLtl4I4drOzA5ii8ny8AzmvLJBgkF

Entry address:
0x3FDE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 50, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 68, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
8 KB (8,192 bytes)

The file lordsofthefallen-ru-languagechanger-v2.exe has been seen being distributed by the following 2 URLs.

http://fra-7m15-stor02.uploaded.net/.../928b5068-f65f-4847-ba1d-f58fc4ebbe11

Scan lordsofthefallen-ru-languagechanger-v2.exe - Powered by Reason Core Security