fap6eval.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.flipalbum.com.
MD5:
035aea23a02896735b97a8a8cffff75f

SHA-1:
9f97ef5df8f1f595d326c84a1ad557b9f0d52efb

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 9:13:16 AM UTC  (today)

File size:
17 MB (17,791,248 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\fap6eval.exe

File PE Metadata
Compilation timestamp:
8/29/2002 11:05:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:zyb+8l07wgh26iJPdOZ0yGfUvhlTUW9WvOWUD5KCpws7QqVCX:cvl0sqmJ1OZQfETF957qs7QDX

Entry address:
0x449E

Entry point:
F2, F2, 81, C0, 4F, F5, A1, 2B, 42, 81, E6, E9, 42, EC, 0A, 0F, AF, F0, C6, C7, F2, 84, D4, 46, 88, E1, F7, C2, 1B, BA, 85, 36, 4A, 6B, FF, 00, 0F, BF, D2, FE, C2, 33, F8, 69, CA, 29, E3, 83, 76, F7, C0, 7D, C7, 9A, 06, 6A, 00, 5B, F6, C2, 5D, F7, C0, 96, C3, 96, 4C, 8B, DF, 70, 09, B5, 78, 89, FE, BE, 9B, EB, A4, 8A, 73, 05, 0F, BE, EC, 22, CD, 33, C3, 89, C2, 8D, 3D, 75, 24, 6E, 21, 86, CE, C7, C5, 70, B2, 6F, FD, 8A, C3, 32, E9, 51, 57, 0F, AF, CD, EB, 02, 8A, EB, 48, 29, FE, 0B, FD, E8, 44, 00, 00, 00...
 
[+]

Entropy:
7.9974  (probably packed)

Code size:
25.5 KB (26,112 bytes)

The file fap6eval.exe has been seen being distributed by the following URL.

Scan fap6eval.exe - Powered by Reason Core Security