wzp.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from 113.171.224.169 and multiple other hosts.
MD5:
fa38245d1ebf77ad4611a1832124141a

SHA-1:
78a9bc1948d98a4b87c3fa87e75060c161c69859

SHA-256:
3daf54b172a242a08fca78dd96487c7d3e290d67688aacd37c86285b8850e02e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 8:04:51 PM UTC  (today)

File size:
2.9 MB (3,041,460 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\wzp.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:7DH/tIRQFZUQm976ooGjNri75RIBcoi3lI4elH2LeJYLQpxo9PMno0SKfoAcRBqt:7DH/iV19XXriNe2H1I468eqLV6no0S8t

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, B6, 95, 1F, 5F, 35, 32, 74, 00, 00, 00, 00, 00, 7F, 00, 00, 00, 00, 00, 00, 00, FA, 8B, 14, 2A, BB, F5, 4D, BA, 59, 07, 00, 40, 56, 18, E2, A0, CC, B5, 24, 82, 28, A1, 7A, EC, 24, 90, F5, 61, C7, 2C, 95, 86, EB, 81, 4C, 47, 2C, 75, 4D, 61, 35, C8, E3, DC, 71, 4C, 51, D0, A3, DD, 27, 1F, EA, C1, 78, 19, 1F, 44, 7D, 65, BF, 5C, DE, 5B, 30, 1F, 39, 51, 68, 23, 40, AE, 41, B2, 8F, A8, 78, CB, 01, 0B, 5F, 40, C6, AA, D5, 6B, A5, 80, 60, 56, 67, 92, 39, 8F, 85, 25, 35, CF, AF, 9D...
 
[+]

The file wzp.exe has been seen being distributed by the following 2 URLs.

http://113.171.224.169/.../wzp.exe

Scan wzp.exe - Powered by Reason Core Security