stalkerpl.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.bytesendclear.com and multiple other hosts.
MD5:
189b4a39ea50630c4d936ced70f8c927

SHA-1:
029f9833276ba1b0de25534330a1be98aa6bf412

SHA-256:
776e931d04c48f9863f6aec65ae09cd9cdacc863dabfb9978c6f64c00785fad2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/29/2024 2:50:51 AM UTC  (today)

File size:
74.7 MB (78,318,859 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\thq\s.t.a.l.k.e.r. - shadow of chernobyl\bin\stalkerpl.exe

File PE Metadata
Compilation timestamp:
4/17/2004 4:09:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1572864:te8whRlcEFXvdAI94Nm9AP2sKDycpukMO6DVCorqlQrWgoo:tUhRlcEF1AA4Nm9KmbMNDVCoGlQiy

Entry address:
0x253CA

Entry point:
55, 8B, EC, 6A, FF, 68, 28, 88, 42, 00, 68, E0, 4E, 42, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 2C, 81, 42, 00, 33, D2, 8A, D4, 89, 15, 44, F3, 47, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 40, F3, 47, 00, C1, E1, 08, 03, CA, 89, 0D, 3C, F3, 47, 00, C1, E8, 10, A3, 38, F3, 47, 00, 33, F6, 56, E8, E0, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, 33, 14, 00, 00, FF, 15, 08, 81, 42, 00, A3, 40, F8, 47, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
155 KB (158,720 bytes)

The file stalkerpl.exe has been seen being distributed by the following 5 URLs.

http://www.bytesendclear.com/IjeFcTOT7ZwnX9oi3VjKU2AbVTmkwseWmNxd08gMKm9BfcKkv1uMZ6 j0gNToZlM_ER_CX7c_CblVI_Pm7tt9kjfgUSSkF7GnmqfXFOgN_Jh7D1lp3mg_Ewog2ORZ7OLFKwnkER4dmdcHgrryBVerWhATVyXGH SZQGopqR68kKG_H2NPk2Sl8kxOB2TwLHzILWaC7EeGQQxi9EOImRRF6GXzRc4Ap Uld8kLGO6ap5fniySH8z_oL5nnw65R1lrgUNUHGiJXqWovWS1cqjWdT1qxfaznWldQ7oA6DbNqYOIB5pM6SOY eylFZpDlqzyMUwDIFj0fxpj3jys X33lYN7C6QaWTWFW_PwFxqUzSCONUoC stQWX3pD7B2rbgrwZKwDwzAu7phpc8Z7wemtyqZrOLwQv5CFewbkWUM0 YXQw7KhnVpdYMkAHjFURAFsg_IiWjRH2 gnNkrWryG11kaOQ8BeMoPMYsDlGDL5pPxw8mFgKroQx9G9m9E1j3Y1m17SgEIcl1N6aithHzuQ_1DZTeOm7PYUAhO636p99yXJnXMaiWQUywfakiVyMlWh8viTffdg7rFAeFZtSUE8GlEAAKE w==-G2kAAGTYtrmEse34RJsFEzlwaGngcME3tnEgb4xRFu4G1mUnfDYDX9T gXWE4f7FzfLv3zMQ2I3XRNgvZkNCI3bYdnaW g1sa xiR64RM3J_ss8L_UaCqgyIVwA=-E

http://www.bytesendclear.com/5UdY_pnFZouxBQ8IM67X4iV9gSibdH54DWcCK8mNpA7OylaZhPtDkM8bzIOvqB1rTkGtR8Gm9Cke2ynn0M OnJK9otaW4Sx54rFcWXbXhx1SKAfnA21MsyG3ly6w8 kXvhTG5Zcq2W0lQmI4PzJbbvrhm9qkD51BQ8WbqGjPVDDZ6LtoIZ3NhzAee1hpNADsvXPDSes1VCJ7q8o1x ooB_G1xLAF0NPoxNnInEKhnCDpDhcz2Vcz8bUrGI9Sly6IHb13g593QgIZT_9KioSFi7P3Yf fSkdf0vYtkB4KtbzlTVEKKqh6XdFfnHzKT7vUiy rt4ljEreeZJMk8l9Ce980331wnJeIZHnd47LINkvEGrig1nQPOoAO2QxzSvqyftfg1aRqvrwJbTt4s HBdJSWg5ZxaNjMcZQlotBxdlFUOaPjSVKLR2pbv xfnWgZpqH03NgJ3MbgdWoczaXYaV3whUgmRjr7_x7DeEnUKGo_wb MLaD5H2NfEifrax7q0pcB56JOY9GL6OWKBcc9G1D7zN D1OxGbisG3K dzYPFhu4R0WFJ7ufo6oJBYY9q0IiQswOZiJ1ooCEeBRgRHbIx0YNZg==-G2kAAGTYtrmEse34RJsFEzlwaGngcME3tnEgb4xRFu4G1mUnfDYDX9T gXWE4f7FzfLv3zMQ2I3XRNgvZkNCI3bYdnaW g1sa xiR64RM3J_ss8L_UaCqgyIVwA=-E

Scan stalkerpl.exe - Powered by Reason Core Security