magicchoice.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.sanhuu.mn.
MD5:
4ebd20bde6a9c0af2478a4c4e0b8b171

SHA-1:
b5073a58ad698930f6c75338d51ccf83dd736419

SHA-256:
58a793b2f20d19356a3fc630da21188126bacc154e2e71bcf96ed2bb9e76d502

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
1/21/2025 11:28:43 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
riskware program Program.PersonInsp.13
9.0.1.05190

IKARUS anti.virus
Virus.Win32.Baidubar
t3scan.1.9.5.0

File size:
238.5 KB (244,224 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\programs\magicchoice.exe

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:X4ADOb09pwvK25cwkL11mAt39C0OYqBuD0TQyjsG:X+yF2qNx1pNC0OYqU0EYsG

Entry address:
0x1000

Entry point:
B8, 30, E7, 4A, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, AF, 7E, CE, 1E, 42, AF, F8, D6, CC, E9, FB, C8, 4F, 1B, 22, 7C, B4, C8, 0D, BD, 71, A9, C8, 1F, 5F, B1, 29, 8F, 11, 73, 8F, 00, D1, 88, 87, A9, 3F, 49, AD, E2, C9, DF, B9, F0, B0, A5, 58, 47, 0F, 29, A6, 3B, 8A, 1D, A6, 03, A8, F4, 7C, 1A, 70, 21, 85, 25, 27, 0A, 3F, CF, 09, B9, 53, 71, 9F, 96, 0C, 53, 4D, CA, 3F, F8, E5, 48, A3, 9A, 9B, 32, C2, 4E, C0, 5C, A8, 85, DC...
 
[+]

Entropy:
7.7613

Packer / compiler:
PECompact v2

Code size:
486.5 KB (498,176 bytes)

The file magicchoice.exe has been seen being distributed by the following URL.

Scan magicchoice.exe - Powered by Reason Core Security