erg.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from elswordhack.net.
MD5:
ce5d15493bfaa2c29eccdfb22511b735

SHA-1:
1acef589cba97f92ed59513d8dd167abc7cc5aec

SHA-256:
b18e101f1a37c7efe2de268768fc094cff5386668d552740173270755781eb70

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/12/2025 5:18:12 PM UTC  (today)

File size:
6.2 MB (6,512,128 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\erg.exe

File PE Metadata
Compilation timestamp:
6/21/2016 4:20:25 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:W7IN/XURcHWOwUgnpFkfCISlxxjCpDh3j7RnKzEdk8:NHWXUgpFkPSlHmTj7RnKzn8

Entry address:
0x32CCB8

Entry point:
55, 8B, EC, 83, C4, F0, B8, 80, 21, 72, 00, E8, EC, 1B, CE, FF, A1, 0C, 9E, 73, 00, 8B, 00, E8, 30, D1, EC, FF, A1, 0C, 9E, 73, 00, 8B, 00, B2, 01, E8, 6A, EE, EC, FF, 8B, 0D, A8, 9D, 73, 00, A1, 0C, 9E, 73, 00, 8B, 00, 8B, 15, 70, B5, 71, 00, E8, 22, D1, EC, FF, A1, 0C, 9E, 73, 00, 8B, 00, E8, 72, D2, EC, FF, E8, 75, C8, CD, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.2 MB (3,324,928 bytes)

The file erg.exe has been seen being distributed by the following URL.

Scan erg.exe - Powered by Reason Core Security