picexa.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.reqxtwma.com and multiple other hosts.
MD5:
f43aba2c92a1443f135c17f3c45d0a8a

SHA-1:
2be899d1d99312d30e63df671dc0e91f9d7fd460

SHA-256:
5e768ec1f45980b16847de8324e1b72395d555e2351fae43b14fd031104299ff

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 10:56:39 AM UTC  (today)

File size:
2 MB (2,068,269 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\picexa.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:fWMiB5TwTPFy9MzN2oVNrAW8IAbONLcqCxz5BDSqPyyxI:fWMiV8N2FLbON4Pxz51SqacI

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, 11, D6, E0, 31, B3, D4, 45, 00, 00, 00, 00, 00, 7E, 00, 00, 00, 00, 00, 00, 00, 2A, 66, E1, AC, BB, C1, 41, BA, 59, 07, 00, 40, 56, 18, E2, A0, CC, 05, CC, 82, 29, 78, 7E, EC, AB, 08, 34, 6B, 18, C5, 15, 53, D8, E6, E9, 61, 7E, 99, 37, 35, 19, 97, 83, 47, 2A, 78, 47, CD, 67, 73, DC, 9E, 7F, 31, F6, E4, 74, E4, 4A, 76, 56, DA, 00, 15, 4C, 98, B2, 79, D6, 7E, 31, 93, D0, 64, 6C, 62, 0D, 5F, A2, A8, 62, 0B, 98, 8C, D7, 23, 9C, 9E, E6, BA, EE, F4, 9F, BC, FF, 1C, 21, 4F, 55, 60...
 
[+]

The file picexa.exe has been seen being distributed by the following 16 URLs.

http://www.reqxtwma.com/Public/softs/lim2/9283/.../picexa.exe

http://113.171.224.203/.../picexa.exe

http://113.171.224.213/.../picexa.exe

http://113.171.224.211/.../picexa.exe

http://201.31.162.81/cache/www.reqxhedf.com/Public/softs/lim2/9283/.../picexa.exe

http://113.171.224.176/.../picexa.exe

Scan picexa.exe - Powered by Reason Core Security