pa.exe

Patch8

HwNL & Fabianator

Publisher:
HwNL & Fabianator

Product:
Patch8

Version:
1.0.0.0

MD5:
65e7802d40d01d89215ae0d1e1c3ad5d

SHA-1:
7f3b6f9a4e9b22d20b5339032fd452f2c160565e

SHA-256:
ef1947e0ac65174816dd8c90742457f3c08918c2f41f2fd81d031db043dd8968

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/23/2025 6:51:17 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
UnclassifiedMalware
17633

File size:
31.5 MB (32,986,510 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2012

Trademarks:
HwNL & Fabianator

Original file name:
Patch8.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\act\pa.exe

File PE Metadata
Compilation timestamp:
11/19/2012 7:02:13 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:5eqjUaAIyYEIsI2RSatjyqJk/mEIEk+9SaMnQ:51jUaAIylBI2AatjyqJk/3tk+Uaf

Entry address:
0x4007

Entry point:
55, 8B, EC, 83, E4, F8, 81, EC, 1C, 09, 00, 00, 53, 56, 57, E8, BA, FB, FF, FF, 8B, 35, 0C, 60, 44, 00, FF, D6, 83, E0, 11, 3D, 11, 01, 00, 00, 0F, 84, 22, 04, 00, 00, FF, D6, 8B, 5C, 24, 14, A3, 0C, 50, 40, 00, E8, 89, FC, FF, FF, 8B, C8, 2B, 0D, 0C, 50, 40, 00, 6A, 03, 33, D2, 8B, C1, 5E, F7, F6, F7, C1, 00, 80, FF, FF, 0F, 85, 8E, 02, 00, 00, 33, C0, 33, FF, 89, BC, 24, 24, 09, 00, 00, 66, 89, 84, 24, 10, 05, 00, 00, 89, BC, 24, 0C, 05, 00, 00, 66, 89, 84, 24, F8, 00, 00, 00, E8, 45, FC, FF, FF, 8B, C8...
 
[+]

Entropy:
6.2207

Developed / compiled with:
Microsoft Visual C++

Code size:
16 KB (16,384 bytes)

The file pa.exe has been seen being distributed by the following URL.

Scan pa.exe - Powered by Reason Core Security