99e6bfe7d0285148c4a72675e11cd165.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from down.xiazaiyuan.net.
MD5:
84d76584ef6624a35436c583a8f8949f

SHA-1:
289a23d83878f1d4392554a824d1a28e5cc332ac

SHA-256:
7a092485f3e7b90843077474a2d7a1d4effbc322f6a64145bc8cafe42423a164

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 4:51:36 AM UTC  (today)

File size:
2.5 MB (2,588,672 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\99e6bfe7d0285148c4a72675e11cd165.exe

File PE Metadata
Compilation timestamp:
5/12/2016 2:58:36 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:QpcYEjlIjroRRbi3Gh9V7qEysVavBhVI7e0/OLwgX/pigZMwkjfv2Cg:Qp1E9RA3Gh9V6KagenpXZZMBjfeCg

Entry address:
0x9154B5

Entry point:
60, C6, 44, 24, 0C, BF, E9, 0C, 51, 8A, 00, 8D, 64, 24, 04, 0F, 83, 26, F4, FF, FF, 9C, E8, C2, 0B, 8A, 00, 9C, E9, 13, 47, 8A, 00, 02, 46, 2F, B9, 10, 23, D3, F2, 08, 1F, ED, 34, 9E, 01, 14, 4F, AC, C9, D6, 65, B1, 5C, 14, 75, 72, 6C, 0B, EE, 0E, 33, 37, 6B, 9A, 2D, FC, EA, 65, 63, 27, 4B, 99, C4, 4B, B7, 45, 70, 0A, 21, DB, 02, 2E, E2, 0A, 31, CB, CA, C0, EF, 0F, 2E, AF, 59, 69, 09, FE, 59, 82, 2B, 19, C4, F7, DD, C3, 28, 45, 3C, C0, BC, EC, B4, 27, 52, 23, 46, B2, E2, D3, 71, F5, 8D, F4, 5C, 29, 41, 22...
 
[+]

Entropy:
7.8304  (probably packed)

Code size:
514.5 KB (526,848 bytes)

The file 99e6bfe7d0285148c4a72675e11cd165.exe has been seen being distributed by the following URL.

Scan 99e6bfe7d0285148c4a72675e11cd165.exe - Powered by Reason Core Security