dat0612.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from 113.171.224.170 and multiple other hosts.
MD5:
1ea510ac9b4611d764df714b13e92d39

SHA-1:
707438f77486400729e79174a07c0c906d8eedff

SHA-256:
de29a0b0e5d9f02122340a05a254cf41f0bfe7883d5110aac774368ebbb01272

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 1:31:19 PM UTC  (today)

File size:
13.9 MB (14,625,457 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\dat0612.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
393216:vGKcMuWzYJHziQ1ksVgfUpAW9bmNoitpoRFaYPD:OKcMuWzYRBACXlSsFaiD

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 59, F3, 77, 2B, A7, 30, 70, 85, 00, 00, 00, 00, 00, 7D, 00, 00, 00, 00, 00, 00, 00, A2, F8, 6E, A8, 00, 40, 57, 18, EA, C7, C0, AA, 29, C5, 41, 4B, CE, 1A, 26, AC, 9A, 44, 74, 90, 2E, A7, 74, 14, 31, CB, 99, 0E, 8C, C7, FE, AD, 11, 00, 52, AD, B1, B4, 49, FC, 85, AC, 72, 33, E1, A4, EC, D5, B6, 9B, F4, AD, DE, 66, 80, 2C, 3B, 26, B5, 88, 12, 61, E8, 50, 1A, 0B, 8A, 25, D9, AF, CC, BD, 00, AA, 10, F6, 2D, 9E, 2B, B4, 12, 10, A7, CE, 0A, 0B, E7, A3, 8D, 9B, A4, D9, 92, 87, C7, F8...
 
[+]

The file dat0612.exe has been seen being distributed by the following 4 URLs.

http://113.171.224.170/.../dat0612.exe

http://113.171.224.245/.../dat0612.exe

http://113.171.224.209/.../dat0612.exe

Scan dat0612.exe - Powered by Reason Core Security