newwzp.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.reqxtmum.com and multiple other hosts.
MD5:
4cc7a792fa37ae2fc019cca74f44b99b

SHA-1:
548db9893c147eddf17595cbce9e385f453347d8

SHA-256:
cb52304a880e857ed16316e91e9c8a0b3921682ed8ade864a32acf38815570fd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:12:56 AM UTC  (today)

File size:
2.8 MB (2,899,844 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\newwzp.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:u5hQGfZtnx9+U5utQ9EzsL8PhYOr6pNS95GREgBMur3pM5wbJ04MLgubw7e72ML9:2fjx9+UYuEKShYOrI09YvBMulM404MLn

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, B1, F6, 44, 2B, 65, 65, 76, 00, 00, 00, 00, 00, 7F, 00, 00, 00, 00, 00, 00, 00, 20, 51, 16, 0F, BB, F5, 4D, BA, 59, 07, 00, 40, 56, 18, E2, A0, CF, 95, F4, 82, 28, F3, 8A, 91, 38, 0E, 05, EB, EA, F0, 7C, A9, 50, BD, 10, EE, FF, CE, 02, C0, 34, 58, 4F, 7C, 3F, F8, A9, 6B, 08, 46, 3A, 25, 43, CF, A2, 0A, FA, 61, E7, 5A, 72, D7, E7, 4C, DC, 76, 13, 03, D4, 07, 4A, 5A, DF, F7, DA, 58, B4, 57, 9A, 32, 0C, 1D, 1D, C7, 93, 3C, 42, 33, 24, ED, 41, B3, BB, D9, 92, 21, AD, 98, AE, 57...
 
[+]

Entropy:
7.9999  (probably packed)

The file newwzp.exe has been seen being distributed by the following 6 URLs.

http://113.171.224.174/.../newwzp.exe

http://113.171.224.206/.../newwzp.exe

http://113.171.224.241/.../newwzp.exe

Scan newwzp.exe - Powered by Reason Core Security