picexa1111.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from 113.171.224.215 and multiple other hosts.
MD5:
90001cb96922d83eeea40092946b7619

SHA-1:
c60c3eacd62149e56a69217985def2fdda4c27b6

SHA-256:
74505afb3e04b1f487c8e0f615fe3475ec192e3e2a3a7f3cd3757f9a93595022

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 12:17:47 PM UTC  (today)

File size:
1.9 MB (2,040,234 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\picexa1111.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:Z9CASlQnKfne1taW56MwTFTWisQrlpERSchNx:Z/QQKfe1mTFTWzQJKQqNx

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, B7, 86, 63, 2B, 3C, 7B, 45, 00, 00, 00, 00, 00, 7E, 00, 00, 00, 00, 00, 00, 00, BB, D1, C7, BA, BB, C1, 41, BA, 59, 07, 00, 40, 56, 18, E2, A0, CC, 05, CC, 82, 28, BD, EF, 40, 12, BB, 36, 56, CC, EE, 51, F4, 1C, 40, 4A, 45, E7, 40, 70, C4, 1A, 39, 83, B9, 2A, 8D, 41, 2E, EA, B8, 45, 5B, 45, 11, 7D, 7F, 2E, FB, F5, C8, DA, 76, 73, D3, B7, C7, 35, 1A, 0F, 68, F0, 57, 35, 87, 05, FF, 21, 02, 13, 09, 45, 40, 80, 30, 09, 42, 0F, 21, D7, BC, 0B, 95, 18, F9, C8, 20, D0, 06, F9, 5E...
 
[+]

Entropy:
7.9999  (probably packed)

The file picexa1111.exe has been seen being distributed by the following 4 URLs.

http://113.171.224.215/.../picexa1111.exe

http://113.171.224.243/.../picexa1111.exe

http://113.171.224.171/.../picexa1111.exe

Scan picexa1111.exe - Powered by Reason Core Security