drop_shadow.exe

MD5:
a9533628b701bb1dd1a87456348df85c

SHA-1:
851ca2cf6b67f7e0615e1f2beab52630e898da23

SHA-256:
df60cf581ad19655dc9ff7edb20e08d164177fd7b4be8565f7d1a188712471b0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 7:19:00 PM UTC  (today)

File size:
65.3 KB (66,856 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\paint.net\effects\drop_shadow.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
1536:0YwqTQ4ZwM8v5sgL2q5ob6u1pE1axZnISxx:0kyHigLnebDE1SZNx

Entry address:
0x824C

Entry point:
55, 8B, EC, 83, C4, E8, 33, C0, 89, 45, E8, 89, 45, EC, B8, D4, 81, 40, 00, E8, EC, B6, FF, FF, 33, C0, 55, 68, 0C, 83, 40, 00, 64, FF, 30, 64, 89, 20, 6A, 00, 68, 80, 00, 00, 00, 6A, 03, 6A, 00, 6A, 01, 68, 00, 00, 00, 80, 8D, 55, EC, 33, C0, E8, 32, A4, FF, FF, 8B, 45, EC, E8, CA, B1, FF, FF, 50, E8, 88, B7, FF, FF, 8B, 15, 24, 92, 40, 00, 89, 02, A1, 24, 92, 40, 00, 83, 38, FF, 75, 23, 6A, 10, 68, 18, 83, 40, 00, 8D, 55, E8, 33, C0, E8, 01, A4, FF, FF, 8B, 45, E8, E8, 99, B1, FF, FF, 50, 6A, 00, E8, 5D...
 
[+]

Entropy:
6.7706

Developed / compiled with:
Microsoft Visual C++

Code size:
29 KB (29,696 bytes)

The file drop_shadow.exe has been seen being distributed by the following 10 URLs.

q=http://ow.ly/p9h0U&redir_token=lLU-CLg3omkkEQF0N1OmNbJeuU18MTQyODA2Mzk2OEAxNDI3OTc3NTY4

q=http://ow.ly/p9h0U&redir_token=S2Uufa3vGM0akLnnNcMnqh3vjcJ8MTQ1MjcwOTQ2M0AxNDUyNjIzMDYz

q=http://ow.ly/p9h0U&redir_token=p3K3C37u6RRje4HOx45kYf_sJ1d8MTQ1Mzg0MDgyNEAxNDUzNzU0NDI0

q=http://ow.ly/p9h0U&redir_token=6QUJmOwaTZdS3CnWTj2DoFttmad8MTQ1MzU4NTI3M0AxNDUzNDk4ODcz

q=http://ow.ly/p9h0U&redir_token=4mdR_klw6TDGzxlQ3ubJ-kX-xex8MTQ0NzkwMzM4NEAxNDQ3ODE2OTg0

q=http://ow.ly/p9h0U&redir_token=rOkVTr3zjRri3zHpYo0PuESiBbF8MTQ1MzAzMzc3MEAxNDUyOTQ3Mzcw

q=http://ow.ly/p9h0U&redir_token=eEP1s1logrDNrOtAhga8S2MqELB8MTQ0NjMxODI3OEAxNDQ2MjMxODc4

q=http://ow.ly/p9h0U&redir_token=SJIS5wE6jDOLcw-qymBQ5dLpxc58MTQwNjgwNjg0NEAxNDA2NzIwNDQ0

Scan drop_shadow.exe - Powered by Reason Core Security