picexa0625.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from 113.171.224.208 and multiple other hosts.
MD5:
c9134810297d2d0e67f73843abdb7822

SHA-1:
e7e1333e357ea4e3024c991bc2b03599f1c997d4

SHA-256:
d68a83f02343ac77c2ee17db9d05f48875688b6b9173299e8fd404fbac2f29d9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 8:43:07 PM UTC  (today)

File size:
19.9 MB (20,917,585 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\c6etna48\picexa0625.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
393216:G86nfB9dDFnpTR3JTeFxQVTjzbcXSd7M3TYOWWW8hWLXZjd4Wom5wShSn:gnp5p13JTeFyJbcMM3TnWDFjloath6

Entry point:
37, 7A, BC, AF, 27, 1C, 00, 03, B3, C2, 78, 50, 0C, 2D, 3F, 01, 00, 00, 00, 00, 25, 00, 00, 00, 00, 00, 00, 00, 73, 1A, A5, 66, 00, 36, 88, 18, CF, 53, E8, 37, 2C, 28, 1D, 6A, 5D, F7, 1E, 2A, 19, 2F, C1, 39, 4C, 31, 99, 69, D3, EE, 7E, 2F, D2, 82, 22, 7F, 1C, E3, B8, AA, D4, E1, C7, 6E, 3D, 8E, 88, 18, 39, 9B, F0, 6D, E7, 5B, CC, BD, 6D, CD, 52, 75, 1A, A8, AF, 98, FF, D8, 6B, 99, 36, 0D, 75, 22, AC, D1, 09, 6B, 3E, B6, 20, E9, AC, B7, 42, 90, BE, 14, 30, 9D, B8, 2E, 15, 04, B0, 42, 48, 33, 8E, F2, D2, A3...
 
[+]

Entropy:
8.0000  (probably packed)

The file picexa0625.exe has been seen being distributed by the following 4 URLs.

http://113.171.224.208/.../picexa0625.exe

http://113.171.224.210/.../picexa0625.exe

http://113.171.224.246/.../picexa0625.exe

Scan picexa0625.exe - Powered by Reason Core Security