winbox.exe

MD5:
6a99967f31076764ae1e284c182c26e8

SHA-1:
b1570964ff5dd93ae793ca2b7bad91d202a8f1c3

SHA-256:
77fd73f2c1d01805a28219aa8f126913b24ace2bd3fe5c8df6e903fdfbc18688

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/25/2024 10:46:21 AM UTC  (today)

File size:
111.5 KB (114,176 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\winbox.exe

File PE Metadata
Compilation timestamp:
2/22/2012 12:36:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
3072:ZkMwuGcvhkLdN3FZJ16ckEdzUdgLlOXu:wuGR7tjkEog0

Entry address:
0x1220

Entry point:
55, 89, E5, 83, EC, 08, C7, 04, 24, 01, 00, 00, 00, FF, 15, 64, B4, 41, 00, E8, C8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 83, EC, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, 64, B4, 41, 00, E8, A8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 8B, 0D, 88, B4, 41, 00, 89, E5, 5D, FF, E1, 8D, 74, 26, 00, 55, 8B, 0D, 74, B4, 41, 00, 89, E5, 5D, FF, E1, 90, 90, 90, 90, 55, 89, E5, 83, EC, 08, E8, 45, 0C, 01, 00, C7, 04, 24, D0, 92, 41, 00, B8, 10, A0, 41, 00, 89, 44, 24, 04, E8, 60, FC, 00, 00...
 
[+]

Entropy:
5.8723

Packer / compiler:
Dev-C++ 4.9.9.2

Code size:
73 KB (74,752 bytes)

The file winbox.exe has been seen being distributed by the following 9 URLs.

http://202.131.245.50/.../winbox.exe

http://62.164.24.1/.../winbox.exe

http://192.168.1.1/.../winbox.exe

http://201.253.108.62/.../winbox.exe

http://192.168.1.1:666/.../winbox.exe

http://192.168.13.1/.../winbox.exe

http://192.168.88.1/.../winbox.exe

http://198.27.66.169/.../winbox.exe

Scan winbox.exe - Powered by Reason Core Security