setup_2115dwfm.exe

美人历

This is a setup program which is used to install the application. The file has been seen being downloaded from xiazai.cdren.com.
Product:
美人历

Description:
美人历安装程序

Version:
1.2.3.1

MD5:
2c4f4c18224feedb09f122867a49a02d

SHA-1:
f5c0437590693c9d11e687f42ddfe60531d43130

SHA-256:
0b47bd25db6a18c590824048e730ea2b51950d976fbe3de4b50cf961246cd8df

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 3:03:33 AM UTC  (today)

File size:
4 MB (4,181,976 bytes)

Product version:
1.2.3.1

Copyright:
(C)美人历版权所有

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\setup_2115dwfm.exe

File PE Metadata
Compilation timestamp:
1/5/2016 9:43:45 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:5UjdIdRjezAJ2hQwq4whUauMko2aL571oXSh6aJq2dy/179S:5UuSC2JcdD2o5DXPY3S

Entry address:
0xD0000

Entry point:
90, 90, BB, 5C, C8, D4, 02, 68, 1E, 00, 4D, 00, 5A, 90, BF, 98, 05, 00, 00, 90, 90, 31, 1C, 3A, 90, 90, 83, EF, 04, 90, 90, 75, F4, 90, B4, B5, D5, 02, 5C, C8, D4, 02, 5C, C8, 94, 02, 35, FC, D4, 02, CC, D1, E9, 02, 84, D7, E9, 02, 5C, 78, D6, 02, 5D, C8, D4, 02, 38, B8, 94, 02, CC, 4A, 94, 02, 26, 4A, 94, 02, 28, A4, D4, 02, D2, 4A, D4, 02, 24, 4A, D4, 02, 38, AC, D4, 02, D2, 4A, D4, 02, 24, 4A, D4, 02, 5C, C8, D4, 02, 5C, C8, D4, 02, 5C, C8, D4, 02, 5C, C8, D4, 02, E0, B8, 94, 02, 5C, C8, D4, 02, 5C, C8...
 
[+]

Entropy:
7.9970  (probably packed)

Code size:
24 KB (24,576 bytes)

The file setup_2115dwfm.exe has been seen being distributed by the following URL.

Scan setup_2115dwfm.exe - Powered by Reason Core Security