picexa1201.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from 41.223.201.247 and multiple other hosts.
MD5:
c8d8b3ad56847e25c80d2af9ed981b10

SHA-1:
b19a02c2ad586b74b008c39d5d164b939c5b8ddf

SHA-256:
c7c555bae6596c4b2dbd55940ce369ddb60b7c2f3e50dd5e128e26aaae7d04a6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 12:19:20 PM UTC  (today)

File size:
1.9 MB (2,041,222 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\picexa1201.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:aPhZa2aIX4Ik9V7GfrSxrUbsH9dOiUYKsIfFZk8KJk53ZiTCq:US2iIxf+BUkYJ50TCq

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, DA, 40, FE, F6, 18, 7F, 45, 00, 00, 00, 00, 00, 7E, 00, 00, 00, 00, 00, 00, 00, 54, 4D, 7D, 3C, BB, C1, 41, BA, 59, 07, 00, 40, 56, 18, E2, A0, CC, 05, CC, 82, 28, BD, EF, 4A, 88, CF, 3D, 84, 9D, 8A, 6C, E8, ED, BA, 55, C6, 7C, EA, DA, 64, C9, 61, D0, 18, F7, AF, 75, C4, F1, 3F, AE, 71, E8, E8, F5, 3C, 9B, CF, 80, 0A, 74, A8, 2E, D2, E9, 09, 6C, 9F, CA, 5E, 6F, 95, 29, CF, FF, 25, 8B, D0, 73, 55, B4, F1, 31, 3D, 08, 8D, 25, 68, BC, 4E, 17, 63, 44, 68, 9E, 26, 9D, 3D, 58, DE...
 
[+]

Entropy:
7.9999  (probably packed)

The file picexa1201.exe has been seen being distributed by the following 9 URLs.

http://41.223.201.247/.../picexa1201.exe

http://113.171.224.216/.../picexa1202.exe

http://113.171.224.246/.../picexa1202.exe

http://113.171.224.245/.../picexa1201.exe

http://113.171.224.178/.../picexa1202.exe

http://113.171.224.178/.../picexa1201.exe

http://113.171.224.211/.../picexa1201.exe

Scan picexa1201.exe - Powered by Reason Core Security