undertale.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from doc-0c-0k-docs.googleusercontent.com and multiple other hosts.
Version:
1.0.0.0

MD5:
5cade42d74c6a6a21671a9026955bcd4

SHA-1:
83c09cb74b9a001998a882f783c757e766c3d66d

SHA-256:
e3e7b599f4a44ae25485294728508696e50fd996652d5ffdc746185bad2ae992

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 6:39:11 AM UTC  (today)

File size:
11.7 MB (12,273,664 bytes)

Product version:
1.0.0.0

Original file name:
WEXTRACT.EXE .MUI

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\undertale.exe

File PE Metadata
Compilation timestamp:
2/17/2013 4:00:50 AM

OS version:
6.2

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.10

CTPH (ssdeep):
196608:lWjf9IyOl4D9DrQltuXTUIh0tCF8gcKb9xZC1dbJIGTvoO38+fsvhoqMAAGce0UM:lw/39DriujUI5wmPIbJTBsCOxMA0CkVp

Entry address:
0x6926

Entry point:
E8, 06, 08, 00, 00, E9, 0D, FE, FF, FF, CC, CC, CC, CC, CC, 3B, 0D, 00, 80, 40, 00, 75, 03, C2, 00, 00, E9, 05, 00, 00, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 81, EC, 24, 03, 00, 00, A3, 20, 87, 40, 00, 89, 0D, 1C, 87, 40, 00, 89, 15, 18, 87, 40, 00, 89, 1D, 14, 87, 40, 00, 89, 35, 10, 87, 40, 00, 89, 3D, 0C, 87, 40, 00, 66, 8C, 15, 38, 87, 40, 00, 66, 8C, 0D, 2C, 87, 40, 00, 66, 8C, 1D, 08, 87, 40, 00, 66, 8C, 05, 04, 87, 40, 00, 66, 8C, 25, 00, 87, 40, 00, 66, 8C, 2D, FC, 86, 40, 00, 9C, 8F, 05, 30...
 
[+]

Code size:
25.5 KB (26,112 bytes)

The file undertale.exe has been seen being distributed by the following 12 URLs.

https://doc-0c-0k-docs.googleusercontent.com/docs/securesc/4r98snr0ukipq86bc2k33uj8mtk32oog/hbls2me30mdsamau878s7pbdkqgafbva/1465358400000/.../06725181394845229890/0B-vFwT31wQaLQjBxVENxYzRhWTQ?e=download

http://www.vaultsapplicationbody.com/c?x=50wIRW6fmn3bGa2AVIq6JDqyV12PBEsOxBOoa9xT5 o=&c=SkFaW L1m90G9PPoSVmyilzYct71AJFQ6B4OVTt4KlyJMJtbZ6FmtWBL0eqr/YciU5VciNJqa1CmsAAppEISXBkakpaTSv7rnS0Qxo78eFRF16m/.../Mj1yikUkL0waWbacoEdHHDjQPm2o0BXfLdoQPklTKE=&e=0&downloadAs=Undertale.exe&fallback_url=Fallback URL

https://dl.dropboxusercontent.com/content_link/.../file?dl=1

http://download1160.mediafire.com/ota65acrogrg/.../UNDERTALE.exe

Scan undertale.exe - Powered by Reason Core Security