C9.exe

Continent of The Ninth

Webzen

This is a setup program which is used to install the application. The file has been seen being downloaded from patch.c9.in.th.
Publisher:
Webzen

Product:
Continent of The Ninth

Version:
2, 0, 0, 0

MD5:
7a6510294f477960f16d5f57b6f5aebb

SHA-1:
103c80089c65b589e44e770c51b39cb4157b1c4d

SHA-256:
8784db9843fd5dc4e5505cb195d55ec2e4917ee28c5bdab2c43fa2556917325e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 10:38:16 PM UTC  (today)

File size:
12 MB (12,583,936 bytes)

Product version:
2, 0, 0, 0

Copyright:
Copyright (C) Webzen 2008

Original file name:
C9.exe

File type:
Executable application (Win32 EXE)

Language:
Korean (Korea)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\c9.exe

File PE Metadata
Compilation timestamp:
4/5/2016 5:03:38 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:VmQaj4bq2UmUVCcaTDkrdGUWEXvPWVID+JINoJDc179R9oILgwPCQ29:UQTFU4NkQFyPWVuMgx9R9pLguCb

Entry address:
0x64010F

Entry point:
76, 06, 01, D7, FE, C7, 84, D7, EB, 02, 86, C6, 22, FC, FE, C1, 47, 0F, B6, C4, 13, CE, 84, C3, 81, DD, 96, 0D, CA, 3D, 29, E8, 81, FE, FE, 93, 00, 00, 0F, BE, CC, 49, 8A, F3, 8A, F1, C6, C0, 95, 2A, FD, 70, 08, 69, C9, 8B, 55, 11, B5, 88, D3, E8, 00, 00, 00, 00, 33, F6, 8D, 15, 6D, BD, 10, 45, 0F, B7, CA, 69, D1, F1, 1F, 85, 5F, 86, C9, 69, F5, 0A, 79, C9, CC, 1A, D0, 4E, 29, F0, 68, D4, 01, 00, 00, 19, EE, 5B, 80, EE, D3, 88, E2, 6B, DB, 08, 22, ED, 85, DB, 02, E1, FF, C2, 80, E9, 6F, 81, EB, 7D, FA, 0A...
 
[+]

Entropy:
7.8966  (probably packed)

Code size:
18 MB (18,891,776 bytes)

The file C9.exe has been seen being distributed by the following URL.

Scan C9.exe - Powered by Reason Core Security