newwzp.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from 113.171.224.175 and multiple other hosts.
MD5:
0476e428edacb7d3f87ec74a004401a5

SHA-1:
9104592a0ac111fb0f3aee3af337b6a1f9034cce

SHA-256:
2047f092092f5575f5185a89defe6b700a72bd1b804d614cbf4a6fa5c5218a85

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 2:56:44 PM UTC  (today)

File size:
2.8 MB (2,901,755 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\newwzp.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:JygqpNZ7Mo0NqNUKRqhUy/Ta64gQRxoOVX0igCMrGOMmdCnb86SxfG8p:Jy/pNZQo0NqjI0gQRhVtQrGkdC0c8p

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, BB, F4, 6D, 94, EC, 1C, 76, 00, 00, 00, 00, 00, 7F, 00, 00, 00, 00, 00, 00, 00, AB, 60, F2, A6, BB, F5, 4D, BA, 59, 07, 00, 40, 56, 18, E2, A0, CF, 95, F4, 82, 28, 35, 94, B3, D4, 55, CD, 77, 88, E5, BE, 04, 6D, CD, 00, FD, 2B, A4, 69, CE, 9C, A5, 1E, E6, C2, D0, 88, 27, 26, 20, 1D, C5, 53, 02, 09, C1, 55, 56, 9D, 1F, D2, 4C, 36, A5, F8, 9C, 6D, 5B, 4D, C6, FC, DF, 9F, 56, A1, AB, 4B, 7E, 26, 5D, 2E, D3, 0D, E8, 6E, 22, AA, 11, EC, D8, D1, 06, 7F, 23, 00, 00, F2, ED, 89, 92...
 
[+]

The file newwzp.exe has been seen being distributed by the following 4 URLs.

http://113.171.224.175/.../newwzp.exe

http://113.171.224.215/.../newwzp.exe

http://113.171.224.245/.../newwzp.exe

Scan newwzp.exe - Powered by Reason Core Security