wintoflash.exe

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.instalki.pl.
MD5:
73643ab23aa112eb0a84984ae55cbd11

SHA-1:
a64d7235ef4402fc02cf4f4c4d8436f15edd92fb

SHA-256:
45f0e8a4e0687c2c3bddcc34130ccb5e04ea720531565576e61d9ebb7e46bf6d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 12:56:00 AM UTC  (today)

File size:
704 KB (720,896 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\wintoflash.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:NLMJf+GKcjF8a7r7PfsI/+wepHlNqOlF2td9lGHvmtiq+lGVyneTDCB:ZMJf+7YF8aLPkGepFNqOlsd/ROGVzT

Entry address:
0x98CC

Entry point:
76, 03, F6, C0, 11, 68, E3, FA, D4, 00, 49, 8A, ED, 23, CD, 84, EA, 1B, F6, 81, FF, 28, C7, 00, 00, 71, 07, F3, 69, F1, 32, A3, DF, D4, 3D, 61, 30, 00, 00, 23, F9, C6, C3, 3D, 0F, AF, FA, 52, 68, 1E, AB, 6E, 00, BF, 9F, 87, 10, F4, 70, 04, 0F, BF, D3, F3, 8D, 35, CC, C6, 4D, 74, E8, 38, 00, 00, 00, 14, 00, 3C, FD, 09, EE, 05, 3B, 43, C2, 6A, 0F, B6, C7, 87, DB, 8B, F6, BA, D3, B6, 00, 00, F6, C3, 29, F7, C7, 67, 09, 75, 2C, 81, F2, 31, E5, 00, 00, 85, FB, 89, D8, 81, EA, 3C, 06, 00, 00, 4B, F3, FE, CC, 2B...
 
[+]

Code size:
36 KB (36,864 bytes)

The file wintoflash.exe has been seen being distributed by the following URL.

Scan wintoflash.exe - Powered by Reason Core Security