internet_explorerpatch.hta

The file internet_explorerpatch.hta has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from 529.ykhve.oovahfamosasbrasil.net.
MD5:
8c5dcaa66224219fe583f1694e76292e

SHA-1:
a7f7e1f29413688e76f89eb887cd80663545d519

SHA-256:
3c5fdd4d898509f6ac4d2030199a5058b0a316321fd8682ca5030a7880ad6cf3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/17/2025 1:50:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Downloader.Meta (M)
15.12.16.12

File size:
557 Bytes

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\internet_explorerpatch.hta

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
12:7amQtf3qnkcbBdS7O9KiVrgNgRIMimngd3pokz1QhUcTQUkaTu4a4cWJW0J78OMa:7amilc0OAWrgatr2ehFrTJYOMa

The file internet_explorerpatch.hta has been seen being distributed by the following URL.

Remove internet_explorerpatch.hta - Powered by Reason Core Security