Windows 8.1 Activator By Ahmad Magdi.exe

Windows 8.1 Activator By Ahmad Magdi

itchno.com

This is a setup program which is used to install the application. The file has been seen being downloaded from doc-0o-88-docs.googleusercontent.com.
Publisher:
itchno.com

Product:
Windows 8.1 Activator By Ahmad Magdi

Version:
1.0.0.0

MD5:
29969b43a20b24c9f1716b0aa12c2408

SHA-1:
3e3715da7170a9a89fe7ab590c0021d1ec454eb0

SHA-256:
b0e7357f8100e102094c21c01e9eca933dc294165739fcc980a55a1a7201c00a

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/27/2024 10:48:40 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/HackTool.WinActivator.C potentially unsafe application
6.3.12010.0

File size:
790 KB (808,960 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
Windows 8.1 Activator By Ahmad Magdi.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

File PE Metadata
Compilation timestamp:
11/8/2013 10:52:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:6VgpYJFGMUYJFGMZ6u+4MU9JktlV0/2YJFGM:6VgYFG4FGLu+jU9Jktz0/PFG

Entry address:
0x8666E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
530 KB (542,720 bytes)

The file Windows 8.1 Activator By Ahmad Magdi.exe has been seen being distributed by the following URL.

Scan Windows 8.1 Activator By Ahmad Magdi.exe - Powered by Reason Core Security