say.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from alpha.tmit.bme.hu.
MD5:
478db27784772b2786ba200d2df7c2db

SHA-1:
34178bf5ad267ecd14efb64e855977eadb5e8558

SHA-256:
fedfaf51028096c70d627f2b28d2c5eb7df86e05474da0fb439d079c7778605b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 4:10:18 PM UTC  (today)

File size:
27 KB (27,648 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\torrent\új mappa\multivox4\multivox\multivoxce\handheldpc\arm\say.exe

File PE Metadata
Compilation timestamp:
5/30/2002 3:56:51 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:

Linker version:
6.1

CTPH (ssdeep):
768:Bd+sDeBQkBgHoYgFk59DMMKcCdpprN9TSx9So9d26I:BjiLkbD9DMMKcCzprN9TSx9So9jI

Entry address:
0x3528

Entry point:
F0, 40, 2D, E9, 00, 40, A0, E1, 01, 50, A0, E1, 02, 60, A0, E1, 03, 70, A0, E1, 06, 00, 00, EB, 07, 30, A0, E1, 06, 20, A0, E1, 05, 10, A0, E1, 04, 00, A0, E1, AA, F6, FF, EB, F0, 40, BD, E8, 0B, 00, 00, EA, 00, 40, 2D, E9, 20, 10, 9F, E5, 18, 00, 9F, E5, 39, 00, 00, EB, 0C, 10, 9F, E5, 04, 00, 9F, E5, 00, 40, BD, E8, 35, 00, 00, EA, 4C, 61, 01, 00, 50, 61, 01, 00, 54, 61, 01, 00, 58, 61, 01, 00, 00, 20, A0, E3, 00, 10, A0, E3, FF, FF, FF, EA, F0, 40, 2D, E9, 02, 60, A0, E1, 00, 70, A0, E1, 5C, 00, 9F, E5...
 
[+]

Packer / compiler:
PocketPC, 0xARM

Code size:
10 KB (10,240 bytes)

The file say.exe has been seen being distributed by the following URL.

Scan say.exe - Powered by Reason Core Security