winproductkey.exe

The program is a setup application that uses the WinZip SFX installer. The file has been seen being downloaded from www.bytesendclear.com and multiple other hosts.
MD5:
a2865a3c6e7c4921e148e3b1231336c9

SHA-1:
8df2d223558f144a09ae3b0dfd631bc3f1855af9

SHA-256:
cb0da1771d751fe307480dcfc33e95e8f39ca74c10ec85d347eab6269fc08e5f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 8:24:21 PM UTC  (today)

File size:
420 KB (430,080 bytes)

File type:
Executable application (Win32 EXE)

Installer:
WinZip SFX

Common path:
C:\users\{user}\downloads\winproductkey.exe

File PE Metadata
Compilation timestamp:
1/9/2001 6:08:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.10

CTPH (ssdeep):
12288:rzXiRiZHeklrTQ7IsDQsDAhIeiWcH9gmJtJ:rzXiRiZHxl/8Iscs0hI3HaA

Entry address:
0x39D8

Entry point:
53, FF, 15, 50, 60, 40, 00, B3, 22, 38, 18, 74, 03, 80, C3, FE, 8A, 48, 01, 40, 33, D2, 3A, CA, 74, 0A, 3A, CB, 74, 06, 8A, 48, 01, 40, EB, F2, 38, 10, 74, 01, 40, 52, 50, 52, 52, FF, 15, 54, 60, 40, 00, 50, E8, 07, F8, FF, FF, 50, FF, 15, 58, 60, 40, 00, 5B, C3, 8B, 44, 24, 04, 8B, 40, 3C, 05, F8, 00, 00, 00, C3, 55, 8B, EC, 51, A1, 28, 84, 40, 00, 83, 0D, A0, 82, 40, 00, FF, 56, 33, F6, 39, 35, F8, 7D, 40, 00, 89, 35, D4, 83, 40, 00, 89, 35, 24, 84, 40, 00, A3, C4, 86, 40, 00, 75, 05, E8, 67, D8, FF, FF...
 
[+]

Entropy:
7.9742

Packer / compiler:
WinZip, 0x32-bit SFX v8.x module

Code size:
18.5 KB (18,944 bytes)

The file winproductkey.exe has been seen being distributed by the following 24 URLs.

http://www.bytesendclear.com/7to7tyAWN2G42gd8YdVO_t0LwsZJJt9tW_jyoILvI4TY7I_isKV6lLCZTfW9RYXVV2IW 7kO4yYBIGlLgwuujUGuYnLJKd6Myaa7s9RYVlIqlBSJW08Mj8nN HaBLcbufLwoM6pzI0bSv2TKZu69I8rED4C0Om1SxAZ_JxB9G8XVyTjBcbtPVaYD9FwSCc1hPx jT1ZMW8_ADwsSCSIJmANcj9mlxOFfuHWZxO_D36mwQdEXVkoPlvbsR4CbWrSllu53bdFwyADSy4wCkqDBelzto7Kw2 gC2IBsIx5cVl_EM1lf5jMa_n08PSzAAr9NVYannSLJDBkWLr72GfyXdNuZJQwfYR3ifFEwiGo0sgALdEhzobn9tS9C9f aGthLrQ820jWj8GLztPDB5quZqPVq EgfW7wrsoE0v_ueCy3PlzQNmqMMXB_y0SF7Ea68JGcjn6p8 zFWXbQZrqKfJ3pMSH4Qgl3uDTUlfeLxzPtANO24rp hHcH9YpqfehAuwcT4ou66Jb5YZeFQxFoztj6qXVt2hkCQzY9Ta6Z6Wjifc1rqang=-GzgAAATqZLH5mi7ABAXgkAP2txJMIA82xs4To0Z Y8bvRJGqFPmJQ sdsMkbBw==

http://poczta.onet.pl/download.html?kid=19183704

http://www.bytesendclear.com/AxlwGNAF8CXUNq1iFiYxxU5X5HwgaNYZxkxDZT6ZvBu6r6GhSIv5uEJKr26Vf3hHM0JfCZYW5 WMFWullcal6q91R2D94eNj NjsYcJmO DgAeVNrwb7TfHZ4OrT2MivZvZagt TFHArDiftJaMrlE94Z888UIoON6BfsnAFr11JMiW5M5i 92qAuPG7Y4a7xJ3H1alDK5dycokuj q8VZl1f4sMl2dSgp4PZfPO6yMGkqUUpflvXE4ywUHgVKUZwHntrrjmgwmYUq_ rKmOv5mpT62xhgLHBv2sq59tzMhKFpgZxxRDbLzDCtGa5c2myDGfRkENjXtIJ6bgXy4lx4KY 8dd2GqqeW q7eyvyN8VMw9qOe40vK04sqrkUTqRlHWiwalpiuhd1qqEkac2QxhkFQqJDxbud19MbcC_DAQtQfDKXBROALZjZ2Y hJXSK1HXlKTRRDVW0tbmrwsPQwqQAiK5SR0GjwJM8HlmkOsWvuS9i3oDXux_bOX pEqc_4IFYDu2yaU8ZTEZm4jiCNRDDEMTfeb0ULKAMyWN3_97etY832REjKDw311MyjyIUxzHXAHi-GzgAAATqZLH5mi7ABAXgkAP2txJMIA82xs4To0Z Y8bvRJGqFPmJQ sdsMkbBw==-E

http://www.bytesendclear.com/zVPvtjjBPu0J3EgOb9StPmZf_q9GNhgnLGu8pTmibC22GLJsI0 UfArTmOUcPsc9xbTQvgRlp8YatqzNFZGHfi4aQy1WgwKrooWy6Wu0UEvrMs9HiBVCQ8h0kP1IBr 23wppIKtgveSfDrvJXZnOMo_Si7NzNQS2XnQHEbiKnBWfcv8PETwkvHFtNr yoXbxfzKdmCpjdva4dR1BGGZ9J0gkwTdnajtsvtb829JL2FK2xLEGUkmiqpOQHHd9WpyrDySPssdY0C2pzAX4KDISU9RVhwbEzQ9g747cj ahMo3i_Pk7Du8xVGIXq33QiVYge7 ni6VOPQtf_xEJQDRID2KCbWhjcv1cUPVW4gQTsgF5Om8DuncRHJPhGIykDY2bcjaP85bMfVSnJgD_RFZhIa28teusTyonH_TymaUm9ESA2nobxbvVRO83EtR5vmexRc1ZvkPleg853hhIeY5K1AzM QEZQw6_XVtuAxqzgiqI2hLuj4SHwd6lp3DUIW2kZgNSI_zVsk Sa89tN4vMheITEm_eblb7a49IUvNpFIEE80_hm w=-GzgAAATqZLH5mi7ABAXgkAP2txJMIA82xs4To0Z Y8bvRJGqFPmJQ sdsMkbBw==

http://www.signtowntoday.com/WVl6OTRQWEJsWkRKUFdtNU9ORFpwT0dkRFZEbFBURlpTT1ZWcGR6RlVkRk5ZUzAxbGJtTjBWeVV5UWxOR1lXYzVTU1V6UkNaalBYaDRNemRYYkRSc2RrVkZOakprTWpCcllYUnJlVTE1WW5GSFRVcFFZU1V5UmxJelpFUjZKVEpDWVZaTGREWkdkalJpYTJwRVJYRnpUbnBTUlZFNU5GTXlOV3g0WlVVbE1rSlhaelpWUmtsaWJEUWxNa0pqTUZCU015VXlSblpqUlZwa1VtUTJRVXhvV25RelJsRnFWVEZoYkhCV1N6RnpTRkJWYW5aUVVVNXVjelo0VkUxS1dWUnRhR3hZYTFvMGVrVWxNa1owTURsVFNpVXlSbUpsUkZkTVYwSkJKVE5FSlRORUptVTlNU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabmQzZHk1eWFteHpiMlowZDJGeVpTNWpiMjBsTW1aa2IzZHViRzloWkNVeVptVjRaU1V5Wm5kcGJuQnliMlIxWTNSclpYa3VaWGhsSm1SdmQyNXNiMkZrUVhNOVYybHVaRzkzY3l0UWNtOWtkV04wSzB0bGVTdFdhV1YzWlhJck1TNHdOeTVsZUdVPQ==

http://www.bytesendclear.com/cdw4g2Unp1IMup67gQf81VQ26o2Ix5RdgLU7 YqS3mxKGkEGlPOEk40 DA5vcYV8godWs EASz9hZQGwtGbn0kZvHYNFksDNAtUiu5TiQy6pLlxl_ 1tBS76pQCEB0_YZrfDl43lb0dXlO3ZlSlqGN fDOrS3jwzh3LOtER4c2jEO7 ex2ZGnCLrjZDed7FsIB5g9PvKicVCFYs5OQ8WzXzKJqJ17rkzsTiG8sFcu47f9C yhmWUQqcJcWqGIRJLD4BmW6lLF1zqXUIxgUVgwmipfmKYSJXAsg_Quo6Vo49 R1jTCLOqVglS75x90IW_NTrp8RzU_vCB_udSgi88mMby bpHIiCHDyVC4f2Qd AOmSJ1xuCn9HAbv9f3djrURH3F_tOSrPS0v5ip9lElLbrgLPvu3K_Zmr0jDT09V2d7KND3TDoIImmUL_wyQxbwVRb5U09vxOx39W7piExJpbKeQkl97foWpyblbi5K7mlU30iFdX4SujNuJtHIucGViRmxbcLaJKzGAbQg1coOWvPlJbFii2_D4GynA xzURfZ32UjC 0=-GzgAAATqZLH5mi7ABAXgkAP2txJMIA82xs4To0Z Y8bvRJGqFPmJQ sdsMkbBw==

http://soubory.instaluj.cz/dwl/e7c66e4f5ba18322ff48bcba35d882a8/utility/systemove-nastroje/ostatni/windows-product-key-viewer/.../winproductkey.exe

http://www.bytesendclear.com/6lXzdI8Wwu3ojKAYCCFiHLnT5PrO1Vv_hD0z_ENMShCrEOh9TDTmWLcZUoYPj2IYzg1CC264BV5SJ1j73gm4PYPMvzTDo5_w3jRvJANs8LIFuKK8FKQIZTLCQtFxpc3i8xPfxErh7b5GCYQ9Zk7KmFMYV9wljULaCf7OTqZPfEXIlr4mi0vXBREZD7QA3zkDEZlBokoWQE34tbAy0WTNqWUQOw8a8k43pnJO0M8gHdshZDeuX38CuBDWP8cNF5llO0NVGVIqKYmZPmO 1hdk7wQQCQz01POYaBAi1mYjB5VTR7NYD GkhAdjbCnyWUmjSt3hnuVqKi1 MhtPtKBuJoL8o iwG86_V3CXtIdR3mD8elzZ mYu_aHqUPWD 0zrx38MB7Tt2diW313q2SnG7fZ9B09UHwXr7c8Gl ArQxQ2aZL mOug4tWaqoKDB9n3kT5qak4jAoXkwrgHwEqGZIPkdq4NmvuwS4IgCHDQ85I07Vxq1nDFhFHcMW84Rt6DnCXTTgTci_CPNsDSIRTJduXcMyACOkmj99cKXLOiwhzHzDqQpxem7L8d1ANoF1EMWP5bXn S-GzgAAATqZLH5mi7ABAXgkAP2txJMIA82xs4To0Z Y8bvRJGqFPmJQ sdsMkbBw==-E

http://www.bytesendclear.com/LQGeF18XXDw2Qy 4pWUdDfJF1VK6GrrsYbziZg3j9Nmjm_iS837ndX_o6fxyCGxXwp YikOKZ5MSpdKB4j9Bc53KIS9JcnPPq43fUlnUF8qo1fchouMQIYpzjWwyf5YT8sfAfApUgvan0_sUIEJnORewNmp0W33tKpgs5nAfPPFmEmwNEATvBHJJ6ZQgPGe47Wl4xZrPW48XoQyNeYdMaoPG3mztgWcVW4C6u4DSbWwrogCmA6G_8q34EZWWNSwsOdkTBOpkJ3AqSHLF1TfzNvzefxyiIPwucVIzlscWTqlFGOxZSTRpCh_lD2GmrN2MEyJ6sW1oNz7oJXhjudhbQICMl_ lu3k0KXX5_jpzF1nxSLQ9_g9PGcYEYUlMFFj_cU2cF9X00CyVgUqq1ejvM92HzAUvKgPBAo9yrezW3oZraQXWMJ5Vnvx_h61dJNc nOICKSB83ydnvhS4KvsRFxZNg_13jv9fm_HqPorv897AMVHFNkQzmhLDNsZoWbtoCgHrkemfA2AK7ZXXd9BUO7OgCO5nfHSr3fugOwDtWaW7mQhlAQY=-GzgAAATqZLH5mi7ABAXgkAP2txJMIA82xs4To0Z Y8bvRJGqFPmJQ sdsMkbBw==

http://www.bytesendclear.com/HIimjxLMppCHVQ26Grcb8 Cop_gMgZZ5APGmN6wWeo4rKGgQWrs3rop9GMwx8YrCqlvhZqDQTOdKcFs4mrwy07iAUSh2jzBhG7x Ym2W K76lRLVl2_aGYZ8_SpseMGGpPwSDe42CLDcoitR2XCXbOoBAo8kBW__18law2tqCeV7Zt1dtJdAMJkYuaEflJlpoX30KlB iIMVqGsaKeKF1wVOY3 PWr4SWYAeAaJ6PSJ0SM1Knwo68uz7J0LCcX99eJF7aAH2 ZiI6QPSARf2O4TEUY8QthlkP3c89Y4HoqrybrVHlOTjW0Cq9L6XZ4Bc5FLTYERtuVwIW0pzT0bdY7PTJBpSEaTUcie1E3qmyJe7uovWZK1y5e1rkb8nfN4rVAXpt424UagVMVE9PHg0MeH2c8MKDqFFE S_QRQ0TZ2FgW0W56pvr_2tIpFtWsPAZLd_ry_yevps0_29RQHV0AQ6ToFRv lL7G7tqz345g NkNOC31QriyRVHdFWTEd4dVd8R6z6mdQ4u_nnwxLHMf _X7N0MmfG5b45rtz9NLsCGRLUZif7n Io5bf6DeXCIrHZWjet-GzgAAATqZLH5mi7ABAXgkAP2txJMIA82xs4To0Z Y8bvRJGqFPmJQ sdsMkbBw==-E

http://www.bytesendclear.com/WVl6OTRQV0UzVVRCRlVYaHJlVTlaUTFnMU1XZHphV1ZTVVZZNVRIbE1TRTFhWXpOT2NFMWhXalk1UmpkVmRVVWxNMFFtWXoxQk1FOWhRelprWVd0NU9FOW1PRGxoYXpSd05YUnhhM05oVkdWNGNrTTNZMWhoZFVFeFpEaFhObEphV1Zwck9HOUVSakYxVGpoU2VVaDBiekV3WldNeVlrOUdiR2wwUlRKS2RVWldhM1pMTkdwMVdsTWxNa1p6WWs4d2VEbE9hREphVFZkdWEzVjROMHhWZFhaTWIwdENjRmxVTmxWbFNXRmphWEpKU0haMllrNHhTR1JMTUZCSGMydExRVXRaVG1wbloxUm5ORVJwUVNVelJDVXpSQ1psUFRFbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1aM2QzY3VjbXBzYzI5bWRIZGhjbVV1WTI5dEpUSm1aRzkzYm14dllXUWxNbVpsZUdVbE1tWjNhVzV3Y205a2RXTjBhMlY1TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVmRwYm1SdmQzTXJVSEp2WkhWamRDdExaWGtyVm1sbGQyVnlLekV1TURjdVpYaGw=

http://www.bytesendclear.com/c?x=MxCJ/LRGizLSa5qfAuLYx 0IgcTftPuEtpnUEeYvtWc=&c=sN9u8JnZ1tMYlvy/h7sbRE0ifJ A8PwPmTTjp78y53x/a 2LEepfGFMqM7kjb/rYVppRAxlSzcs/HjYz MA9EXUVgKflOYYUevGRXG4lhctCO9iMIRmsSe nIrcPChHjUMzj9 ij9OFzui axRv2Bw==&e=1&fallback_url=http://www.rjlsoftware.com/download/.../winproductkey.exe&downloadAs=Windows Product Key Viewer 1.07.exe

http://www.bytesendclear.com/eNXYlv8arr5n8wW_ 9mIGLI6gY4lZfuNAKqJ_fEe3LmWMv_HSLPHf2rgNL91GKU3rEd5GvdglJe6n2XKgU_bnSCbETa5nEWu4zkki0EfL2J3QDXr5ALmnfC1nnCOG jweDNafmzIGOncHQdCdTAhoDpUyqjl7hU w_rTBEjt37 99egTDe0RJgHzbpnj1yA7AYkMZFM_ BHfcDEFrMrOFaqxeWrx447YEYxeZoXr1zw3JIWVtw5VQZUPBYHH5in2s6JFmsBft5cXmpAagEdhPrhn2jJ5dEApPrBMm2TVvMS3 ohtfd7570SgzU dod5Ft8UmwvFLAatVDkFVcP0X52O9q9KilUTbdeexpVp 9Npu9VAH_8h tVvdZdiQFg4gccINcBy9NUW8r0XvD8WadEAb hsnCMf6fbRJd 2WURyh48Bs7DcoBzkJATHszBU1CXlH3HHrRz8YGaylxGD3fV5mBD7awyVjI6N_NxbuEbFYVbZZCDEVCue8WmkKGCl4W5uyjNSofpvQFJQmCjaYVEvXRKyyhER4maTMZcr5nL4o 1w_7wtKSVskjgqADignDsJKaijV-GzgAAATqZLH5mi7ABAXgkAP2txJMIA82xs4To0Z Y8bvRJGqFPmJQ sdsMkbBw==-E

http://soft.mydiv.net/win/dlfile924d3_305559/.../winproductkey.exe

Scan winproductkey.exe - Powered by Reason Core Security