wzp.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from d26yaxxlnmhaem.cloudfront.net and multiple other hosts.
MD5:
adb44b7492115878aee9c194062777f6

SHA-1:
55ab0f4980465e6d11e61705e61b2d2a56141b08

SHA-256:
34e925c2ce9047ffa77c729e289c4f7d63113c6c53d81c50e9369cbfc94465ea

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/8/2025 4:28:53 PM UTC  (today)

File size:
2.9 MB (3,042,729 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\wzp.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:kqCe3YV88PTIQvqK16Tu8GlyYYFom5raNSAF/xofk8sOyFyVoyXJ1BUcP75ZsJU:Ce3y/TMJZYYFJ52NSmo8PjmT9P75j

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, E5, A6, 9E, 00, 3E, 37, 74, 00, 00, 00, 00, 00, 7F, 00, 00, 00, 00, 00, 00, 00, 66, 83, 06, F2, BB, F5, 4C, BA, 59, 07, 00, 40, 56, 18, E2, A0, CC, B5, 24, 82, 28, A1, 7B, 1F, B6, 60, F6, 11, AB, E1, 68, 78, 3E, 48, FE, 05, E3, FB, 80, EF, 57, 45, 5E, 3B, 87, 01, F6, D1, CB, E5, FB, 84, 11, 11, D5, 9A, F6, D2, 3B, C5, C8, C4, 13, C2, 52, 6E, D6, 6F, 92, 17, DC, 52, 5A, F3, 0D, 19, 81, 25, BC, EA, 06, 28, 4D, 86, A1, 61, 8E, 70, 87, DD, 69, 9C, 14, C7, 51, 0C, E2, 37, 86, A0...
 
[+]

Entropy:
7.9999  (probably packed)

The file wzp.exe has been seen being distributed by the following 2 URLs.

http://d26yaxxlnmhaem.cloudfront.net/Public/softs/wzp/2.2.67/.../wzp.exe

Scan wzp.exe - Powered by Reason Core Security