hao123saudi.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from sa.hao123.com.
MD5:
0a1bc5da73cb32145911d30fd5393c7a

SHA-1:
9ceb3d0a13c63842ca379603c79f56da086ef7fe

SHA-256:
126bd8e097fde795dd1c76bb0fba552dab4a871130143ffc9fa0eb1cf9e1294b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/12/2025 8:25:56 PM UTC  (today)

File size:
564.3 KB (577,818 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\hao123saudi.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
12288:yx8388h//vt7Vcq2x57z+0/19zMlD9SGv4ycfskYPQ2sn6aESxu:yxG88h//vtGxMe1VMlDoGvFkYPQL6a4

Entry point:
1F, 8B, 08, 00, 00, 00, 00, 00, 00, 03, EC, FD, 07, 58, 14, 4B, D3, 3F, 80, 0E, 51, 44, 70, 51, 41, 51, 51, 51, 31, 62, 40, 11, 05, 11, 05, 61, 11, 15, 70, 91, 64, 20, 88, 02, 2E, 2B, 49, D8, C5, 88, 8A, 0B, 2A, AE, 98, 73, 46, CC, 39, 67, 11, 4C, 98, C5, 8C, 19, F3, E0, A2, A2, 22, A2, E0, CE, FD, D5, EC, 82, 9E, F3, 9E, F3, 7D, EF, 97, FE, F7, DE, E7, 39, AB, CD, F4, 74, AC, AE, AE, AE, AE, AE, AA, 99, F1, 1A, 36, 9F, D1, 61, 18, 46, 17, 81, E3, 18, E6, 28, AE, F4, 73, D6, 5C, FF, A3, 4B, 21, 32, 6B, 37...
 
[+]

Entropy:
7.9997  (probably packed)

The file hao123saudi.exe has been seen being distributed by the following URL.

Scan hao123saudi.exe - Powered by Reason Core Security