setup_2115bale.exe

美人历

This is a setup program which is used to install the application. The file has been seen being downloaded from xiazai.cdren.com.
Product:
美人历

Description:
美人历安装程序

Version:
1.2.3.1

MD5:
d0209a3760a12c1d1acc5b3fa09f5c43

SHA-1:
0d35cf617bd2494cb66c36e0c1504229a859b84e

SHA-256:
0c56ed40ef38344f527cb9ac3d17bce86afd7868c3e16a3de1a750d254c00ce4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 8:05:42 PM UTC  (today)

File size:
4 MB (4,181,980 bytes)

Product version:
1.2.3.1

Copyright:
(C)美人历版权所有

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\setup_2115bale.exe

File PE Metadata
Compilation timestamp:
1/5/2016 9:43:45 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:KUTdIdRjezAJ2hQwq4whUauMko2aL571oXSh6aJq2dy/17Cz:KUeSC2JcdD2o5DXPYU

Entry address:
0xD0000

Entry point:
90, 90, B9, B0, C7, D4, 02, 90, BE, 22, 00, 4D, 00, BA, 98, 05, 00, 00, 90, FF, 34, 32, 31, 0C, 24, 8F, 04, 32, 90, 4A, 83, EA, 03, 75, F0, 90, 90, 90, 58, BA, D5, 02, B0, C7, D4, 02, B0, C7, 94, 02, D9, F3, D4, 02, 20, DE, E9, 02, 6C, D8, E9, 02, B0, 77, D6, 02, B1, C7, D4, 02, D4, B7, 94, 02, 20, 45, 94, 02, CA, 45, 94, 02, C4, AB, D4, 02, 3E, 45, D4, 02, C8, 45, D4, 02, D4, A3, D4, 02, 3E, 45, D4, 02, C8, 45, D4, 02, B0, C7, D4, 02, B0, C7, D4, 02, B0, C7, D4, 02, B0, C7, D4, 02, 0C, B7, 94, 02, B0, C7...
 
[+]

Entropy:
7.9970  (probably packed)

Code size:
24 KB (24,576 bytes)

The file setup_2115bale.exe has been seen being distributed by the following URL.

Scan setup_2115bale.exe - Powered by Reason Core Security