bomb-buddies-es-en-fr-de-it-win.exe

Balanced Worlds (Beijing) Software Co., Ltd.

This is a setup program which is used to install the application. The file has been seen being downloaded from dw.uptodown.com.
Publisher:

MD5:
0468d1cea2ef759e15f214a8d01b3fa0

SHA-1:
bc320c46c11dbc3de81956759ebbb72120e2c384

SHA-256:
e0e6136bc838359062b4271335c93bfd67f5d8a064e55b400cb00434dcbadc5e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:19:59 PM UTC  (today)

File size:
2.8 MB (2,972,928 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\bomb-buddies-es-en-fr-de-it-win.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
4/5/2012 2:00:00 AM

Valid to:
4/10/2013 2:00:00 PM

Subject:
CN="Balanced Worlds (Beijing) Software Co., Ltd.", O="Balanced Worlds (Beijing) Software Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07A581482809A37EBF5DBB652DF621E4

File PE Metadata
Compilation timestamp:
6/20/2012 10:15:23 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:oCA4hTPORj/VFNHO/kRq5olri1rEjEflTw:oCAI2jVucT1oAjEflTw

Entry address:
0x60EC3

Entry point:
E9, 88, C6, 04, 00, E9, 73, 02, 03, 00, E9, 3E, 1F, 01, 00, E9, 59, DD, 02, 00, E9, E4, D0, 05, 00, E9, FF, 54, 02, 00, E9, 6A, 59, 01, 00, E9, 45, 90, 06, 00, E9, D0, 4F, 06, 00, E9, AB, B8, 04, 00, E9, 26, F9, 00, 00, E9, 61, 83, 0B, 00, E9, CC, F2, 08, 00, E9, 57, 85, 08, 00, E9, 42, 00, 08, 00, E9, 1D, 39, 06, 00, E9, 18, 67, 04, 00, E9, 53, 58, 05, 00, E9, 2E, 50, 03, 00, E9, 79, 83, 08, 00, E9, 9C, 32, 04, 00, E9, BF, CE, 03, 00, E9, 14, 32, 04, 00, E9, 35, 0F, 04, 00, E9, E0, 95, 04, 00, E9, 7B, 8E...
 
[+]

Developed / compiled with:
Microsoft Visual C++ 8.0 (Debug)

Code size:
782.5 KB (801,280 bytes)

The file bomb-buddies-es-en-fr-de-it-win.exe has been seen being distributed by the following URL.

Scan bomb-buddies-es-en-fr-de-it-win.exe - Powered by Reason Core Security