winbox.exe

MD5:
6eecb628260755708725e5aa6a61800e

SHA-1:
970b717e534593aee8003a9edf7151e5a6b80d0e

SHA-256:
5c1dad189c23e407470b9f07415e6a660aa8f2835acd64cc580b385c63a45baa

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 4:18:16 PM UTC  (today)

File size:
111.5 KB (114,176 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
1/29/2013 3:38:10 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
3072:KkMwuGcvhkLdN3FZJ16ckEdzUdYLlOXu:ruGR7tjkEoY0

Entry address:
0x1220

Entry point:
55, 89, E5, 83, EC, 08, C7, 04, 24, 01, 00, 00, 00, FF, 15, 64, B4, 41, 00, E8, C8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 83, EC, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, 64, B4, 41, 00, E8, A8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 8B, 0D, 88, B4, 41, 00, 89, E5, 5D, FF, E1, 8D, 74, 26, 00, 55, 8B, 0D, 74, B4, 41, 00, 89, E5, 5D, FF, E1, 90, 90, 90, 90, 55, 89, E5, 83, EC, 08, E8, 45, 0C, 01, 00, C7, 04, 24, D0, 92, 41, 00, B8, 10, A0, 41, 00, 89, 44, 24, 04, E8, 60, FC, 00, 00...
 
[+]

Entropy:
5.8725

Packer / compiler:
Dev-C++ 4.9.9.2

Code size:
73 KB (74,752 bytes)

The file winbox.exe has been seen being distributed by the following 17 URLs.

http://www.gremiobpchoque.com.br:809/.../winbox.exe

http://192.168.1.254/.../winbox.exe

http://192.168.0.39/.../winbox.exe

http://amescontabil.no-ip.org/.../winbox.exe

http://192.168.49.1/.../winbox.exe

http://192.168.2.21/.../winbox.exe

http://172.16.5.1/.../winbox.exe

http://19.84.1.1/.../winbox.exe

http://192.168.88.1/.../winbox.exe

http://192.168.1.2/.../winbox.exe

http://10.0.0.1/.../winbox.exe

http://192.168.0.254/.../winbox.exe

http://7.7.7.2/.../winbox.exe

http://192.168.1.1/.../winbox.exe

http://192.168.2.1/.../winbox.exe

http://192.168.100.1:8888/.../winbox.exe

Scan winbox.exe - Powered by Reason Core Security