setuptango.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from update-cdn.tango.me.
MD5:
6a0de3dfbd5b8dbd88614c2676788943

SHA-1:
f4e545b262a667bf27072aae5045adb10e8675ce

SHA-256:
967d9589fafdb1c84747addbb37056549a4237343b2b817d83c5d5117a671f70

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:03:14 AM UTC  (today)

File size:
11.3 MB (11,848,672 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\setuptango.exe

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:m7IbcYWjeajfa2O2rC0YycYBJ3415qZWLuGC5GEB7++CJbJzjKMnmbfwIXQu:0IQYWyaG211x3I1cZWLPClBS+WxK/fwY

Entry address:
0x30CB

Entry point:
40, 8A, FC, 39, C8, 34, D0, 80, F6, 68, 0F, AF, D8, BF, 8F, B1, 8E, A8, 4A, 89, ED, 0F, AF, EA, 8D, 05, 91, 9A, A5, 21, E8, 00, 00, 00, 00, 09, F1, 0F, B7, D9, B5, 8E, 8D, 1D, 0B, FC, ED, 3A, 81, EF, 5F, 51, 00, 00, 69, C7, 8C, F6, 48, 33, 69, CD, AF, 56, 72, 01, 81, C7, CF, 00, 00, 00, 5B, 8B, FD, C6, C4, 64, 23, C2, 0F, AF, FA, 4E, 46, F2, 89, DE, 85, D1, 81, F9, 17, 8C, 00, 00, 0F, BE, C2, C6, C2, D8, 0D, EA, 57, B0, 08, C7, C6, F3, D6, B8, 4B, 33, D2, FF, CE, FF, C0, 86, D0, 40, 8A, CE, FF, C1, 89, CA...
 
[+]

Entropy:
7.9674  (probably packed)

Code size:
22.5 KB (23,040 bytes)

The file setuptango.exe has been seen being distributed by the following URL.

Scan setuptango.exe - Powered by Reason Core Security