epic pen setup.exe

Epic Pen

Brian Hoary

This is a setup and installation application. The file has been seen being downloaded from windows.indir.com and multiple other hosts.
Publisher:
Brian Hoary

Product:
Epic Pen

Description:
Epic Pen Setup

MD5:
e1ff8bc6db4de45244c97a0bac1bfcb8

SHA-1:
f4ecf856d74968ebebf9a405291465d70f21c795

SHA-256:
ca6e945deff23ff67f5c15a3eb4570ecbf993da11a07ca28e77a9a0086021be9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 12:46:31 PM UTC  (today)

File size:
1.9 MB (1,978,037 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\epic pen setup.exe

File PE Metadata
Compilation timestamp:
10/13/2013 11:19:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:p1TpF8jfzHMPiMZQdpXFVXGxZFAxwZ/OYIoi:r9FsfzHMP6dFej2jx

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9558

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file epic pen setup.exe has been discovered within the following program.

www.Toolwiz.com
About 1% of users remove it
 
Powered by Should I Remove It?

The file epic pen setup.exe has been seen being distributed by the following 14 URLs.

http://windows.indir.com/kaydet.php?x=TXpJeE5EbEFRRUFoSVNFdVFYTnVLelJtSlcwMVRRPT18fHw0ZWY4ZTAzNWU4MDNiNmU2NmU1NmYyMTNiZGFmYjcyZA==&m=1

http://windows.indir.com/kaydet.php?x=TXpJeE5EbEFRRUFoSVNFdVFYTnVLelJtSlcwMVRRPT18fHw1NTljZmE5YmY3YzViZWU0MzU1ZmIwZDQ5YWNjMmFiYQ==&m=1

http://www.bytesendclear.com/H6pZzurV LagZZPP TzK96pXfMmrsqOOgOsvgWSIv3_PtUpYPMk8w6pIbmMyU4acSeYIU6sfc8iV4WHHaXJe VR_NyvW8yxuuAMqeONUpsK nb1m7ESn1WhyqmV7wEud0Xh4ue9dkgewRyHNOcsHe7ZNE3Trsve2E4LhljERkJhVrpFi0UZDhLRFQvxNgFuHIO7nRPBCDlUhZ9aG8Qvkv88dxiwqzvohDAtg9aUOo642Rab BRjtvd3 mGophwCIO8iDnvfpQcoOXfh_iYQVoOeMvwQbhd2e9if0uQooLsHzOPR5ffU2KjEZ2B SIIdI5qxSu2ypwdApmdnex56NZuyHE_v3dCsQYH1z3cR5R4g6ZX54HijejJlRgL0s PE0encPqpCnYHifTxh1KLp_EvZKXy7hiMiVqTPvZilXFM38cqbfT3lLUriO_9dIoR9RnlNJubGjk2MwnrSbGubvaCF1uOyum1jnhdaviUZBlrXGK97eCYA01ppYxDVh0O5WEF7I2Y_Y6FRLyYNqDAq9xLK5NSCzHvrtrOvMML5MmoJF6m mTCAlLYrWZEeLaPF2hF96dxU6PdS2DpMaqDlXBIWVbZAfy57mDGigUkYlAcKtpw3G3Uq5FHXYBbXXLQfifGEazyzK-G28AAGTcXExAyFdfR_xqjnHgcMMy6ED QDJ4DK_ll0N58I2xyKDuA67LTsVsB7Ho_YPriJyBy2PZLU1Kuv9S_JbmARZog2SeJQpWy2s5e2EK7uR5rVC Eg==-E

http://windows.indir.com/kaydet.php?i=32149&x=TXpJeE5EbEFRRUJJWVZOQVRqZzNNdz09fHx8ZjJhZjA0YzM1Y2I0NzY2Y2VmMzJkZTg2M2RlMDg2NDA=&m=1

http://windows.indir.com/kaydet.php?x=TXpJeE5EbEFRRUFoSVNFdVFYTnVLelJtSlcwMVRRPT18fHxlNmYzMjQ3OGE4NzM5YzE3MmQ4YTE3ZGM1ZmEyZjI1Yg==&m=1

http://windows.indir.com/kaydet.php?x=TXpJeE5EbEFRRUFoSVNFdVFYTnVLelJtSlcwMVRRPT18fHw2ZjJkMzE5Nzg2MDMwZmNkZjEzNGVjYzhhZDRlNWUyOQ==&m=1

http://windows.indir.com/kaydet.php?x=TXpJeE5EbEFRRUFoSVNFdVFYTnVLelJtSlcwMVRRPT18fHxmOTE1ZTc4ZWIyYzI0NjdiYTg4MmZiY2JhZDg5MmM2OQ==&m=1

Scan epic pen setup.exe - Powered by Reason Core Security