ooo-3.4.4-1-win32-ux.pl.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.bytesendclear.com and multiple other hosts.
MD5:
113b74dae03905594dd9c5167fd87b85

SHA-1:
b88d4b863ff90599d721186aaac1bf7fd692a0d7

SHA-256:
b6b691395634a26c2a08867d2cee19d4038031eb90375ad128c3651b216427e2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/26/2024 6:29:47 AM UTC  (today)

File size:
273.3 MB (286,615,567 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\ooo-3.4.4-1-win32-ux.pl.exe

File PE Metadata
Compilation timestamp:
5/3/2008 4:08:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6291456:P+1bGjlQxK0C7vn1v1Lvv8tg21AgEYNTHZ:P2igK97vnT4b1AY

Entry address:
0x30E3

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 58, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, E1, 2A, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 90, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 4C, 91, 40, 00, 68, 60, E3, 42, 00, E8, 98, 27, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 86, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file ooo-3.4.4-1-win32-ux.pl.exe has been seen being distributed by the following 12 URLs.

http://www.bytesendclear.com/5W0yG5FAM9jemFJc01meC5D1i1b_TkMv6Qx H5QHVotn4gB_kl6yyrth9wiL_pe8z3OTr1sSNnqrJDL_5VZzNiwAixIFGec3cQgYkE93Y1Qq_PBLZXAJHZ7wiD06y9zVQnaMkqyB9Y9Y6QtZBLxLwN6IO5vt1Ms5AsN85e0FnsOP5jvD8s67i2X kuOMI5idFWbYhAoSm7DEs DOJu7aNymxEs58DH0yJAcH5ZUtVsW08qIFKScRfd40BiW4o3sNi6Muq1QucqLfTZ15z3on97 hCVkJtC2vdW7fHQMSZMji69 nesKXmUpqqmUVKM2rJaU0pjfkUyyXuDezk_ PUx7Tyw3yhu03WTTtw2kcofn8FSEg2YJ8FUQD4DZEisX8A6X9bI5k5VWbflcWKo07MtRc5a2OJk3SBX9UJQIyaZh4GOq2V0Vh47uG8EBLOzgxR9upsOl9reDTSlXwcSLr9PCTkgqOZQcVz9 eBHkm9WjENchoigo_6LNGsr_AvMwEEgQUKLoK3kMH Rdt7TxM0GbBAwrMMj9tT7J36i2GHN5NMuNrTLmepUBPegWVFGT0i4LO_sjAiXVy6AKNemJmY8g9ZT wFA==-G2MAAGTYtrkAYzyfK3KTaYNDDhy a2YBSaDBRE4kaEuud40pCtB9YIoFs6Ati7L8MDnU6bvEfiyYYjRiq_n14345GhIPXzzz9o0ODUMEhw5tA 4PJgf5xwE=-E

http://www.bytesendclear.com/amAS_cyK2b4N40eiU5oXi8_sh8KpcI2 wWdyTGgtu0y8K9_F_hjnrkHkQ0YAxNBcj36CUx0ecQgQorUL0BLlBCrxzMdAIYZTbaioxIZwN1bhb_1CfCgWnweG70mpfYPmTWPsgFeXIPAv hU0EHcCjT6tcIwQHTahW5ueQm9mH1j28iTjseAFSsbwKoiVOB WzFzYwMdwbqAJ4eK_BAei _P4X5q7tKZz6w1vQ8PNoZsCfeLRId6crDgDcK9pq8f dBegT13ksEXlvaCeJ97aaCPZ3yjTSCNbX4msD53fzgYvyR0du1ckFjgNQiWnscf7nlOZwZPixy1S0Pzlm1weiCXp2nHe1WicQ0pcnWuYpHUxPDvNUB0UHzUA9bYMAZcCMO63fnXIJqnpjDLoDB3BcR7l JdjsLPZ4_lPB22LUnY2pZ9_gzF6RJNIhzFud9nT9vSu07wWmO4sV4G3eIfgnZ7vgQynZDx3fsmUrN2G2URKdG7OQRMEUGc2l5QWDFNtlaMapFtyOZAzNw0eWLH6AJ jSrKmP3lJgOv5w4XXTR3vNxRJlYxvrXPAVE7eFSoziYafUHI7CRX8R7g0FajuFoF8eZrSjg==-G2MAAGTYtrkAYzyfK3KTaYNDDhy a2YBSaDBRE4kaEuud40pCtB9YIoFs6Ati7L8MDnU6bvEfiyYYjRiq_n14345GhIPXzzz9o0ODUMEhw5tA 4PJgf5xwE=-E

http://s6930.chomikuj.pl/File.aspx?e=Lmjh4aDfFVtOiWPjc24KQwixvAXAYG6Q1gXcXEJgOhDPjfidqjVJjWRVVgQotGXXYbH-ntQgj7tXerh4IUuNdxYlq9pZ9vVcn8hBPGexgiPV0JjPqZkaV4UydRilBDPjRdx9syI3yLN615ksrUxh3IiBdYARW_ABJ8ojMyfj5UA&pv=2

http://www.bytesendclear.com/36_byR4nFpIG6fKIGK0st8gMibZJoNs7Od42zXyiuZr_QWGQ1Fn69v B0dhy9g8rAmsfiKeNBRg2ZUoTpdhvJ4wGkMyYB8wh2bf1FDRcW_FxwZ_zXjQzfog1MSfNpEUL6LkRR2FkgM D9VpiGhcQNcfZj6DrrVGO6hhY1QLMiCkHn3sfzTUfvp2k4SX5FUCY10IUoLw9amUf1mPDdZnxZJsLFELvGzd8dQj3j5POg jiHnQNidOV_hK_X1od3EeMUmyC8RmQwcL8TUu4LTfU7_CYBsTCTrkKhR7HgQa7ylbT2CfGKL3VDzQIVjJLvoE5gOA9kQCxGJ3MLEdGTGzd3zak6mHdVNRvVxeCBY5EFh7 twAqJAaYNd8b_BVn5bGvzpmLW7ZtMqA1vd BnjnFqoB36umaQriH6ezf4B3NCgmxuEk9bpnjjEpwSiZP7Leov6RKBP0gBLkdMuT2qTxHiWl3wSn lMGvpdtE HnPSHi3oV4g5XTjG6D4MkxOZ4ULIXl3sJ6gfcdyqwMykDtEW4mZb0AO 227 PzCVPc8Q1aLFq3wVMcP_PMJFX6zE5eCg_koCMGrpv4L51tIREPPdwJa4luSs9HWPShJKIJMCCcAab5tveo=-G2MAAGTYtrkAYzyfK3KTaYNDDhy a2YBSaDBRE4kaEuud40pCtB9YIoFs6Ati7L8MDnU6bvEfiyYYjRiq_n14345GhIPXzzz9o0ODUMEhw5tA 4PJgf5xwE=-E

http://ux.pl/.../dl2.php

http://178.33.48.31/programy/.../OOo-3.4.4-1-Win32-ux.p(programy.net.pl)l.exe

Scan ooo-3.4.4-1-win32-ux.pl.exe - Powered by Reason Core Security