picexa0611.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from 113.171.224.216 and multiple other hosts.
MD5:
3ae61fecfd0883c36a7fc32aa3841bcd

SHA-1:
6cd0d7696f47114c546baa3bd2f13c35cde162af

SHA-256:
d8132c0e7805818028e84166f57618e26ae9608a0467652db424bfcd3c37ec86

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 8:15:13 PM UTC  (today)

File size:
19.9 MB (20,890,180 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\picexa0611.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
393216:9RFgesIGwk2mBN+Pp3dVsZjFOl1SgiQD/A+0HCGM8PrGPU1QDCNIsQedc:lges/874FOl1HbSHC3NPU1CCNhi

Entry point:
37, 7A, BC, AF, 27, 1C, 00, 03, 9C, 34, 80, A9, FF, C1, 3E, 01, 00, 00, 00, 00, 25, 00, 00, 00, 00, 00, 00, 00, 04, 36, 51, D3, 00, 36, 88, 18, CF, 53, E8, 37, 2C, 28, 2C, 8C, 44, CE, EC, 93, 83, C9, 8D, AE, 18, 55, 00, 64, F8, 91, C5, AA, 4D, EF, 1D, 84, D7, A6, 21, 0B, CB, 40, F7, 46, EB, 05, 7B, 7C, 9E, 33, D8, 84, 0B, 38, B6, 11, 49, 45, 34, 41, 0D, 6D, 43, D9, DB, CA, E7, DA, B7, B9, C9, 87, 4B, E1, BC, A8, DE, 1A, E6, 05, FF, 44, 41, C2, 1B, FB, 85, 07, A5, 44, BA, 0B, 79, 6A, 29, 72, 31, 20, EC, 7E...
 
[+]

The file picexa0611.exe has been seen being distributed by the following 5 URLs.

http://113.171.224.216/.../picexa0611.exe

http://113.171.224.177/.../picexa0611.exe

http://113.171.224.204/.../picexa0611.exe

http://113.171.224.169/.../picexa0611.exe

Scan picexa0611.exe - Powered by Reason Core Security