diskdigger.exe

DiskDigger

This is a setup program which is used to install the application. The file has been seen being downloaded from download2124.mediafire.com and multiple other hosts.
Product:
DiskDigger

Version:
0.8.3.176

MD5:
d851f242ca8f6824466d5f129dea3c95

SHA-1:
b0b444fe3880e88f82bd89d45bc394c6f8bd4505

SHA-256:
ce2be87d1b68040795a9b5869a4906ef902d3bf0cde77bba196358f9fad2200e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 2:58:25 PM UTC  (today)

File size:
1.4 MB (1,511,936 bytes)

Product version:
0.8.3.0

Copyright:
Copyright © 2009 Dmitry Brant

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\diskdigger.exe

File PE Metadata
Compilation timestamp:
7/19/2009 9:47:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
24576:tCDj7XV2ik5sk7WyDC38kTm9It4oA6ZXhwIfBr3D5Ss34YTt7H9NrSD8QU8NXuIy:tCDj7XV2ik5sk7WyDChK4v9D5SmB7GDt

Entry address:
0x163C

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, 8C, 70, 51, 00, A1, 7F, 70, 51, 00, C1, E0, 02, A3, 83, 70, 51, 00, 52, 6A, 00, E8, 01, 4B, 11, 00, 8B, D0, E8, 12, ED, 0D, 00, 5A, E8, 34, EC, 0D, 00, E8, 47, ED, 0D, 00, 6A, 00, E8, 1C, FE, 0D, 00, 59, 68, 28, 70, 51, 00, 6A, 00, E8, DB, 4A, 11, 00, A3, 87, 70, 51, 00, 6A, 00, E9, BB, 81, 0E, 00, E9, 4E, FE, 0D, 00, 33, C0, A0, 71, 70, 51, 00, C3, A1, 87, 70, 51, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, E4, 00, 00, 00, 0B, C9...
 
[+]

Code size:
1.1 MB (1,138,688 bytes)

The file diskdigger.exe has been seen being distributed by the following 9 URLs.

http://download2124.mediafire.com/mvz2v79c8tog/.../DiskDiggerfull.exe

http://download2124.mediafire.com/rq72u75xhueg/.../DiskDiggerfull.exe

http://download844.mediafire.com/r0w8nuxslu9g/.../DiskDiggerfull.exe

http://download2124.mediafire.com/mn3qcpe0m73g/.../DiskDiggerfull.exe

Scan diskdigger.exe - Powered by Reason Core Security