ns_com639c03.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from fs08n5.sendspace.com.
Version:
1.0.0.0

MD5:
6e8b91c627e8e580caf156b7de2a844a

SHA-1:
ce4b5aa97f48dc0ae414e5ddb4e2a5d333d9d50d

SHA-256:
100fa163021950637f0ed7333b5e05870f852934afef6bb9f738bd0965be07d6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 5:35:41 PM UTC  (today)

File size:
8.5 MB (8,916,480 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
French (France)

File PE Metadata
Compilation timestamp:
4/9/2016 9:36:42 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:iijpvqmaQElOQyaZqBsI8iFDLKCdGQWv6dLzMm5ZuvNEMM6R0XKxZc:3ufyaZqB/8ip5HdXM+ZCEMM6KXI

Entry address:
0x1803E44

Entry point:
60, C7, 44, 24, 1C, FF, 89, 0D, 03, E8, 48, A2, FB, FF, 9F, 8B, 45, E0, C7, 04, 24, A4, 16, 94, 93, 8D, 64, 24, 24, 0F, 8D, 66, 37, 3D, 00, 60, F7, D0, 9C, 60, C6, 44, 24, 0C, 19, FF, 34, 24, 8A, 04, 38, E9, 3A, 08, FD, FF, 6E, 77, 55, DA, DE, 5A, 06, 38, 95, DA, 88, 9E, B1, 7C, CA, 8F, F1, B6, 9E, 56, 1E, 72, FC, DC, 00, 9E, 18, CF, 67, C3, 32, 4B, 16, 7C, 41, 83, 48, 36, BB, D9, 34, 86, 4B, 2D, B2, 2C, F1, 6F, 34, 26, AB, 17, D5, 89, B1, D8, 40, 7E, 24, 8E, 80, EA, DF, 23, DA, CC, 06, DB, 6C, 67, 82, B7...
 
[+]

Code size:
14.4 MB (15,090,688 bytes)

The file ns_com639c03.exe has been seen being distributed by the following URL.

Scan ns_com639c03.exe - Powered by Reason Core Security