635495861528801949.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.wiziq.com.
MD5:
fd3d504fc7b15e009c992b4f8ef3b19e

SHA-1:
17b22f358204bf03b8927a9e59a320965f96f901

SHA-256:
fd451099fadc6e5e8f6b413803d870802caff2a7c4e3db975def0c891ccb089e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 2:48:22 PM UTC  (today)

File size:
26.8 MB (28,152,122 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\635495861528801949.exe

File PE Metadata
Compilation timestamp:
11/1/2008 5:03:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:1oues3KrjOktC2S6DxntcNFWQhrmPMHwjg+:5UjHtC2S6Dxn8BhCPMQ8+

Entry address:
0x61124

Entry point:
F3, 8A, F5, 89, F0, BB, 09, 44, 22, 4A, C6, C4, EF, 84, D6, 01, F7, 80, C7, 36, 3B, C8, EB, 0F, 69, D8, 4F, 43, 7F, CC, 69, DD, BF, 02, 5E, 94, 0F, AF, D2, 81, FE, A8, AC, 00, 00, 73, 05, B5, 11, 0F, AF, F1, 33, C0, 72, 05, 0F, BE, F6, B5, EC, 8D, 1D, E2, C0, 33, A5, F2, C6, C5, 0A, 86, EB, BE, D0, F9, FF, FF, 8D, 1D, 8F, BE, 98, 7E, 81, C6, F5, 02, 00, 00, 87, ED, 0F, C1, F0, 02, D4, 01, C3, 05, 3C, 03, 00, 00, 69, EF, F7, 31, C8, 56, 32, ED, 49, F2, 0F, AF, F6, 3D, 12, 0A, 00, 00, 0F, 82, B6, FF, FF, FF...
 
[+]

Entropy:
7.9949  (probably packed)

Code size:
472 KB (483,328 bytes)

The file 635495861528801949.exe has been seen being distributed by the following URL.

Scan 635495861528801949.exe - Powered by Reason Core Security