_password.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.svenbader.de.
MD5:
e5eb59a145d3593ca02c12034871366d

SHA-1:
0fbe6bcf2770d487d23ca9b2a1c85a1829d3fb8b

SHA-256:
1185f68091dd729ba8b349fc385af7c7d6464d419710d3f3a73db28030a51479

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/18/2024 9:04:42 AM UTC  (today)

File size:
125 Bytes

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\_password.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
3:vAeMLwwPyeXQ1FCFXV/bfd1+KiNFLtRyoV44joEziHnAwn:vJwhn/bfd11Y5RBV/jZzkL

Entry point:
50, 61, 73, 73, 77, 6F, 72, 64, 2D, 46, 69, 6E, 64, 65, 72, 0D, 0A, 0D, 0A, 41, 43, 48, 54, 55, 4E, 47, 3A, 20, 41, 75, 66, 67, 72, 75, 6E, 64, 20, A7, 20, 32, 30, 32, 63, 20, 53, 74, 47, 42, 20, 28, 48, 61, 63, 6B, 65, 72, 70, 61, 72, 61, 67, 72, 61, 70, 68, 29, 20, 6B, 61, 6E, 6E, 20, 69, 63, 68, 20, 64, 61, 73, 20, 54, 6F, 6F, 6C, 20, 6C, 65, 69, 64, 65, 72, 20, 6E, 69, 63, 68, 74, 20, 6D, 65, 68, 72, 20, 7A, 75, 6D, 20, 44, 6F, 77, 6E, 6C, 6F, 61, 64, 20, 61, 6E, 62, 69, 65, 74, 65, 6E, 21...
 
[+]

The file _password.exe has been seen being distributed by the following URL.

Scan _password.exe - Powered by Reason Core Security