gifcon.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.thaiall.com.
MD5:
7410055d875d254a9bf67614773293d1

SHA-1:
18f2b0d51ff7cc46904c02b07b220d01ac929f69

SHA-256:
7eea4ac0e8dbbee933a938e5bab031c8e2a98d3c234bad5692a8f62998ca4215

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 10:50:47 PM UTC  (today)

File size:
1 MB (1,055,744 bytes)

File type:
Executable application (Win16 EXE)

Common path:
C:\users\{user}\downloads\gifcon.exe

File PE Metadata
OS version:
2.13041

OS bitness:
Win16

Subsystem:
Native (none required)

Linker version:
3.0

CTPH (ssdeep):
24576:/kSgKXLHjc6o8tyWoUK969OA1LzMuuXGBuyr97yZGui9N:/kSg4LDJtt2UR9O8LzMuipcui9N

Entry address:
0x123011B

Entry point:
4D, 5A, 50, 00, 02, 00, 00, 00, 04, 00, 0F, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 90, 00, 00, 00, BA, 10, 00, 0E, 1F, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 90, 90, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 6D, 75, 73, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 75, 6E, 64, 65, 72, 20, 4D, 69, 63, 72, 6F, 73, 6F, 66, 74, 20, 57, 69, 6E, 64, 6F, 77, 73...
 
[+]

Entropy:
7.8494  (probably packed)

Code size:
256 KB (262,147 bytes)

The file gifcon.exe has been seen being distributed by the following URL.

Scan gifcon.exe - Powered by Reason Core Security