winmekmak_016.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from x.vindicosuite.com.
Version:
0.16.0.50

MD5:
df38138e04227839bc3b97c8dde86b3c

SHA-1:
513dd844e209d890a3602a7d74bb6268b4d55f63

SHA-256:
5e0a5ac937bd5d83a2f65e4291b5cd1e23858e3b5cdebddb7bb0d7cddd0dbf56

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/3/2024 8:46:38 AM UTC  (today)

Scan engine
Detection
Engine version

Quick Heal
(Suspicious) - DNAScan
7.16.14.00

File size:
595.5 KB (609,792 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Swedish (Sweden)

Common path:
C:\users\{user}\downloads\winmekmak_016.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:NQrFeMKYasGjxKSOpkVY+xVNsrfJckFRQmNXoF6eKyC2gc:NQeVsG1KSOPaNszJJVe59CL

Entry address:
0x1000

Entry point:
68, 01, D0, 5B, 00, E8, 01, 00, 00, 00, C3, C3, CF, DA, 8E, 18, 29, 00, C7, 9B, 52, B0, 30, 0B, 4C, 72, CA, A9, 81, CD, 23, D4, 6B, 31, 47, DD, F5, B7, AE, 37, C7, E3, 51, BE, 4F, E0, CE, 93, 0B, 32, B8, 86, 2D, 53, FE, 46, 76, 1F, 1E, A6, 5C, 0F, 6F, F2, A0, FF, 1A, 7E, 61, E1, 0B, BC, FF, D2, EC, 6D, AB, EA, 26, 0B, 93, 58, 2E, AD, 34, AA, DE, 62, 26, 72, 7E, A1, 70, 27, 16, 79, 37, E2, 52, 47, 2B, F7, D4, AA, EA, 10, F3, 31, 24, DD, E9, 91, D1, 8D, 79, 4D, A0, A0, 5E, E3, 4D, FD, D2, 6E, A7, 5D, 8C, FB...
 
[+]

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
504.5 KB (516,608 bytes)

The file winmekmak_016.exe has been seen being distributed by the following URL.

Scan winmekmak_016.exe - Powered by Reason Core Security