TFMCheat.exe

TFMCheat

This is a setup program which is used to install the application. The file has been seen being downloaded from fs02n5.sendspace.com and multiple other hosts.
Product:
TFMCheat

Version:
1.0.0.0

MD5:
261c88a74c73d8b1eb74fefd543d7e7c

SHA-1:
f8ffd9e163213f1780f204e7c6568ae10319d54e

SHA-256:
4a056495f95fd549ecbfc2deeb51277cadc4a8ec7fc9fc9cc28ae796c1ba4167

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/25/2024 4:32:30 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/HackTool.CheatEngine.AF potentially unsafe application
8.0.319.0

File size:
4.5 MB (4,685,824 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2016

Original file name:
TFMCheat.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\tfmcheat.exe

File PE Metadata
Compilation timestamp:
4/3/2016 9:33:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:PjXUXKFM3qXvmzJGjDGN/sS3DS9WraIhseSLdjbAccB2dEby:SKW+TjDqU/9WN6ZjbDdEb

Entry address:
0x4686DE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
4.4 MB (4,614,144 bytes)

The file TFMCheat.exe has been seen being distributed by the following 33 URLs.

https://fs02n5.sendspace.com/dl/31fa4119a64afbad4f75cf3fdb8084ad/5880110b3d01acc3/.../TFMCheat.exe

https://fs02n5.sendspace.com/dl/12d581322c086f3e004f02906f46d145/5726a0cf03e2d84c/.../TFMCheat.exe

https://fs02n3.sendspace.com/dl/36da8e39ff3bbca42379f3165098ce66/587070896ac23520/.../TFMCheat.exe

https://fs02n2.sendspace.com/dl/7533d32392599c1ee48bd2657c4012b1/5872bd09692f0829/.../TFMCheat.exe

https://fs02n5.sendspace.com/dl/c24faaac3b70c40385746e8164e7057c/586fd0d4252e86c3/.../TFMCheat.exe

https://fs02n3.sendspace.com/dl/42bb57703c76977bba9eeaa98953a610/57327ecd11a66ad6/.../TFMCheat.exe

https://fs02n4.sendspace.com/dl/e2a5e715ff46e0260f245376bb6f4beb/57fa90bf18d52a91/.../TFMCheat.exe

https://fs02n4.sendspace.com/dl/ee54b3bf2196f79d878ed2105664556b/5786b69b2d30e418/.../TFMCheat.exe

https://fs02n2.sendspace.com/dl/2b842e4049c09883280b6b40f319bea8/572be06f09156105/.../TFMCheat.exe

https://fs02n3.sendspace.com/dl/18aa24b55602c80d943a187d14bbf504/57e99bdc1ec82e0d/.../TFMCheat.exe

https://fs02n1.sendspace.com/dl/3c9c0cdb8cfd10ebc641163ed17769b2/581b36ff0214131d/.../TFMCheat.exe

https://fs02n2.sendspace.com/dl/c4344ca53c26bab1ac5308bbcca97fc9/57aba52e6a9b7634/.../TFMCheat.exe

https://fs02n2.sendspace.com/dl/cda33659c893f359ab9dbf58b07cd51b/57801ddb310df9c1/.../TFMCheat.exe

https://fs02n3.sendspace.com/dl/a45b8d50040b7ee063478877c39912f5/584ca4a313a818db/.../TFMCheat.exe

https://fs02n4.sendspace.com/dl/930c98bf082e9c97449103249f620976/58330dfd7123a854/.../TFMCheat.exe

https://fs02n1.sendspace.com/dl/af1db323f23c9ec652a0a51876dce157/5838afe55dc86907/.../TFMCheat.exe

https://fs02n1.sendspace.com/dl/bae73015f7cacd6853ad30663bb6d709/57e348e201d31fda/.../TFMCheat.exe

https://fs02n5.sendspace.com/dl/3e811db89ce5b4b365a30e2c40b4532d/57fe695f5b975045/.../TFMCheat.exe

https://fs02n2.sendspace.com/dl/96509c1fad795d770b7670db48d2a7f4/5727d2ad13d1aac8/.../TFMCheat.exe

https://fs02n4.sendspace.com/dl/f995f8b6c2cb9f51453c56aaf977d766/581701f757b7bef2/.../TFMCheat.exe

https://fs02n5.sendspace.com/dl/4ddb7182b5d262d58e0e1964b3365a30/58136c0a3fbd495a/.../TFMCheat.exe

https://fs02n1.sendspace.com/dl/e281f982288a27828a7df4d63f2c3d11/581cfd421f507857/.../TFMCheat.exe

https://fs02n5.sendspace.com/dl/ff6428959d324724ccbcda90cba37a73/5839004670779b91/.../TFMCheat.exe

https://fs02n4.sendspace.com/dl/423e1d09cba2cca0cf6df8a73e727232/580132da1bc11fcc/.../TFMCheat.exe

https://fs02n5.sendspace.com/dl/883f5f1f3f28966dbd0f92a97963880e/5817bcb44725778b/.../TFMCheat.exe

https://fs02n1.sendspace.com/dl/3680f33011b3c33ca6d1ea7b88f49ddb/57a6e33b0abe27a6/.../TFMCheat.exe

https://fs02n4.sendspace.com/dl/7dbf6877b52db7ac1fae0fa67a159cc7/57cc2a2964f4eae2/.../TFMCheat.exe

Latest 30 of 33 download URLs

Scan TFMCheat.exe - Powered by Reason Core Security