ef8m5s14.tmp

XMind

XMind Ltd.

Publisher:
XMind Ltd.

Product:
XMind

Description:
XMind 7 (Update 1) (v3.6.1) Installer

Version:
3.6.1.0

MD5:
f19649c0dee1f4bf1630da24f37424e9

SHA-1:
4efccd41a3630649f83b3bf8f5d824a88dae4424

SHA-256:
40267d26e9d9fd3bb40766b69aa41aac2fbd158fb91cffc338f2809af05584f0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 2:54:52 AM UTC  (today)

File size:
142 MB (148,861,426 bytes)

Product version:
3.6.1.201512240104

Copyright:
Copyright (c) 2006-2014, XMind Ltd, All rights reserved.

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ef8m5s14.tmp.download

File PE Metadata
Compilation timestamp:
7/9/2014 2:58:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3145728:fnFK7L3n8NdMOdhsCbwxmHq3SEQL75JYDNMoTs6kTa7/Q9TF27Zv7ykn3qHM:fnF6ad7hJwxm2SzUA65Q27l7ysAM

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9998

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file ef8m5s14.tmp has been seen being distributed by the following 13 URLs.

http://117.17.205.40/HS/sub_box/.../xmind-7-update1-windows (1).exe

https://doc-0k-bs-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/754sjqc00l35ruub99p3e8od8177nrqq/1471392000000/13264473942182366320/.../0B7NgoINNntruX0FuZUJzbEsyUXM?e=download

http://dl2.xmind.net/171E92C18EEE40A29D1749C505091DFC_SOPHOS_WARN_PROCEEDED_FLAG

ftp://10.20.203.80/Utilities/.../xmind-7-update1-windows.exe

Scan ef8m5s14.tmp - Powered by Reason Core Security