windows.kodi.thewiz.pack.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from tiny.cc.
MD5:
2e8eb067ec67363ec02feb5725295afc

SHA-1:
0316bca34ac28dc95c45a9f311dff64cc5098ef3

SHA-256:
b0dea9d2e24995e3de57d4ed491e292ae581f400714d31f4e2597e1a941f9f96

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/4/2024 5:14:12 PM UTC  (today)

File size:
198.2 KB (202,992 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\windows.kodi.thewiz.pack.exe

File PE Metadata
Compilation timestamp:
8/5/2015 3:46:33 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:N9KRQS4/CAvKmRQHf3zCFjrkJiUgPH/ubXl:Nz/CjHfjCFkgUEO

Entry address:
0x30E2

Entry point:
60, 85, D7, 4E, 1D, 74, CF, 8C, 2D, 2B, E8, 72, 02, B6, 26, EB, 06, 8D, 0D, 61, FB, CA, 13, 81, FF, 6E, C1, 00, 00, 76, 0A, 3C, 8F, 84, ED, 81, DA, 27, 69, 3A, 3F, 81, C3, 28, 4E, 00, 00, 84, D2, 81, EB, 2F, 0A, 00, 00, 0F, AF, EE, 81, F9, A6, 49, 00, 00, 72, 06, 8D, 35, D2, 1F, 3F, 93, 31, DA, 68, 55, AF, 44, 00, 55, 23, EA, F3, E8, 2A, 00, 00, 00, 88, F7, C6, C7, E3, 34, AA, 88, DC, 0F, AF, EE, 73, 06, 89, CF, B4, 8F, 8B, FB, 8D, 18, 0F, BF, C5, 89, F1, 0F, BF, F8, C7, C1, D2, 76, 0D, BA, 33, D3, 84, DD...
 
[+]

Entropy:
7.8795  (probably packed)

Code size:
24 KB (24,576 bytes)

The file windows.kodi.thewiz.pack.exe has been seen being distributed by the following URL.

Scan windows.kodi.thewiz.pack.exe - Powered by Reason Core Security