MD5:
cb5e100e5a9a3e7f6d1fd97512215282
SHA-1:
11f9578d05e6f7bb58a3cdd00107e9f4e3882671
SHA-256:
ca00fccfb408989eddc401062c4d1219a6aceb6b9b55412357f1790862e8f178
Scanner detections:
0 / 68
Status:
Clean (as of last analysis)
Analysis date:
4/17/2025 10:35:44 AM UTC (today)
File type:
Executable application (Win64 EXE)
Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\rmp.exe
Code size:
62.6 MB (65,596,588 bytes)
The file rmp.exe has been seen being distributed by the following 6 URLs.
http://www9.afsanalytics.com/cgi-bin/click.cgi?usr=00916632&exit=http://www.4pockets.com/games/.../4pinballexpansionlevel(cyberstorm)demo.exe
http://s1.1zoom.ru/big3/.../Vikings_(TV_series)_459743.jpg