ftweak-hex.exe

Febooti, SIA

This is a setup program which is used to install the application. The file has been seen being downloaded from x.febooti.com.
Publisher:
Febooti, SIA  (signed and verified)

MD5:
4129baa2942879ae6ceda9b037b70b41

SHA-1:
0da683a634d8f2e7f366823839964d6ff7e5a0e1

SHA-256:
008ff6d222e43e52b8a83b2e892208925df7bdfc5b960a7067a8512a1ec3150f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/1/2024 11:45:28 PM UTC  (a few moments ago)

File size:
696.5 KB (713,168 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/9/2014 7:00:00 AM

Valid to:
5/10/2019 6:59:59 AM

Subject:
CN="Febooti, SIA", O="Febooti, SIA", STREET=Citadeles 2, L=Riga, S=Riga, PostalCode=LV-1010, C=LV

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0099B0466BFC77EB6E8A3EE7C6207E28C4

File PE Metadata
Compilation timestamp:
8/28/2015 11:33:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:iD+W1RO0boeTmlWEXp3dTX7mjHkLJFSxrWTNSyXYZuDAkfpX1wT8u:d0bTWp3drhLScTNSYY+AkhXiR

Entry address:
0x3E39

Entry point:
E8, 5E, 1A, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 48, DF, 40, 00, E8, 59, 18, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, E0, 0F, 7E, 00, 77, 22, 6A, 04, E8, 49, 1C, 00, 00, 59, 83, 65, FC, 00, 56, E8, 50, 24, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, 65, 18, 00, 00, C3, 6A, 04, E8, 44, 1B, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 44, A0, 40, 00, 83, 3D, 24, 0D, 7E, 00, 00, 75, 18, E8, 1B, 09, 00...
 
[+]

Entropy:
7.9381  (probably packed)

Code size:
35.5 KB (36,352 bytes)

The file ftweak-hex.exe has been seen being distributed by the following URL.

Scan ftweak-hex.exe - Powered by Reason Core Security