cgiwrw506zb.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from teleimagem.dyndns.info.
MD5:
ca11ce69b1961f69f89e86b291c754d9

SHA-1:
dd41a97b39d6b234ddc80f8813e0e9621cccb90c

SHA-256:
3c1283c5439c4b5a1dfc6af7074bb460354fa816056a28e3a84d1ed6877dc908

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 11:15:13 AM UTC  (today)

File size:
907 Bytes

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\cgiwrw506zb.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
24:J6id509ASfEmU/yXrptq2QxEWOBFsxG0iL1I:J6cmel/crpM2QmW2Fsoh1I

Entry point:
9E, 4F, EF, 16, DB, 64, 82, ED, 65, B9, 5C, ED, 36, FB, 74, F6, 45, 31, 97, 4C, 24, 53, F9, F4, 36, 15, 3C, AC, 53, 69, 93, E9, E5, 4E, A9, 55, A2, 56, 64, 00, 1E, 3A, 4D, 38, 03, C1, 41, 00, 71, 4C, A5, D3, 89, A4, C2, 5D, 31, 98, CC, E6, D3, 19, CC, BA, 6C, 03, 10, 9B, CD, 40, 80, 33, 39, 84, E0, 08, E1, 30, 9C, CD, 26, D3, 29, 94, E2, 6B, 31, 99, 4D, 66, B3, 80, 2C, 00, 14, 42, 6F, 37, 9B, 01, 4C, 26, 93, 39, A4, D6, 6D, 33, 98, CD, A7, 13, 99, 10, 08, D2, 89, 41, AA, 51, 40, 5C, 13, 29, 80, 1A, 00, 0F...
 
[+]

The file cgiwrw506zb.exe has been seen being distributed by the following URL.

Scan cgiwrw506zb.exe - Powered by Reason Core Security