question grabber.exe

ask.fm bot 2

Product:
ask.fm bot 2

Version:
1.0.0.0

MD5:
1ef9e5692fa1b351aa76afcf720a8d4c

SHA-1:
4abb1f1575c841b6992d05a97366751296d9b90b

SHA-256:
952eaeaea4fc529673d32455568abc86daa7c4357969b7986c7c896b6d298691

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 11:13:28 PM UTC  (a few moments ago)

File size:
32.5 KB (33,280 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
ask.fm bot 2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\question grabber.exe

File PE Metadata
Compilation timestamp:
10/14/2013 1:21:50 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:2fX4L66dck32BgOA5l3rn6RG6XkxAfHFcLk24jXPlaIuoW/SYiHfBDt:f1p32BgOA5pfS9lw2XP0s9t

Entry address:
0x687E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.9837

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
18.5 KB (18,944 bytes)

The file question grabber.exe has been seen being distributed by the following URL.

Scan question grabber.exe - Powered by Reason Core Security