$rwfn8ba.exe

Playtech Software Installer

Playtech Software Ltd.

This is a setup and installation application. The file has been seen being downloaded from banner.kwin22.com.
Publisher:
Playtech  (signed by Playtech Software Ltd.)

Product:
Playtech Software Installer

Description:
Kwin casino

Version:
1, 0, 0, 1

MD5:
dcbed6d3ad9a1a8d7ffeda848858d834

SHA-1:
47ff1dc45054958fca2ca79a6b9eaf1ebc0462bc

SHA-256:
9da82ab6e7b341617754f15be0a9ddeb01654f4b19d409f53ae4f1fc500b4bad

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 11:42:55 PM UTC  (a few moments ago)

File size:
321.1 KB (328,840 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2001-2009 Playtech

Original file name:
CasinoDownloader2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/9/2012 8:00:00 AM

Valid to:
2/9/2015 7:59:59 AM

Subject:
CN=Playtech Software Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Playtech Software Ltd., L=Douglas, S=Douglas, C=IM

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5179D5766F1C0C23B16399371E1F02C5

File PE Metadata
Compilation timestamp:
10/27/2012 3:00:35 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:fppJQwsvDZ/8ZfmjNQYo4QfxqYcbaz81gBrCo69yuU9eOo5x94F2HW:GxEmjCAQf0Yhz3rj6d/E2HW

Entry address:
0x33B7C

Entry point:
B8, 00, A7, 58, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 3D, 54, 77, CF, EE, 5B, 3D, 4D, 5D, EE, FA, C8, 7A, C9, E3, FD, D4, A6, B8, 25, 79, AD, BF, 62, 0B, 3E, F9, B0, 1D, 33, E6, 3E, AC, 45, BB, 2E, 91, ED, B0, 39, 29, 5F, 07, 39, 11, B1, 22, 6C, EC, 8F, FC, FE, 86, 52, 5B, 1D, 19, C3, 38, FF, F5, 65, 14, 7F, D3, 11, 45, DA, 18, 45, B3, 6D, 33, 7F, 00, 90, A3, 9F, D4, 40, C9, 37, 1A, 5A, CA, F9, C2, 95, 0D, 16, E9, EC, 1D...
 
[+]

Entropy:
7.8193

Packer / compiler:
PECompact v2

Code size:
331.5 KB (339,456 bytes)

The file $rwfn8ba.exe has been seen being distributed by the following URL.

Scan $rwfn8ba.exe - Powered by Reason Core Security