windbot1092-2.7.8.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.tibiaiwindbot.com.
MD5:
596f44ac1c63fe3fa833c08d2f48cc97

SHA-1:
69fd54933891fd6aba2e85c767970f498f757e71

SHA-256:
b16cf553a7ea1cadf9964243a7845f1254011e58d0d93cbe2b020e36d195639d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 10:06:54 AM UTC  (today)

File size:
17.5 MB (18,393,088 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\windbot1092-2.7.8.exe

File PE Metadata
Compilation timestamp:
3/3/1991 8:07:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:a2/vpRJ3ip23gVeuAwLl455ILNXwS+jSdU6fiF4zkpsMZCMURsJ:HzJ3f3gVLls5iXwZSdU6fW4zIJZVfJ

Entry address:
0x6CDE4

Entry point:
55, 8B, EC, 83, C4, F0, B8, 24, CC, 46, 00, E8, A8, 98, F9, FF, A1, 4C, 6E, 47, 00, 8B, 00, E8, 84, 9B, FE, FF, 8B, 0D, 38, 6F, 47, 00, A1, 4C, 6E, 47, 00, 8B, 00, 8B, 15, 80, C6, 46, 00, E8, 84, 9B, FE, FF, A1, 4C, 6E, 47, 00, 8B, 00, E8, F8, 9B, FE, FF, E8, BB, 73, F9, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
432 KB (442,368 bytes)

The file windbot1092-2.7.8.exe has been seen being distributed by the following URL.

Scan windbot1092-2.7.8.exe - Powered by Reason Core Security