zalo_123.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from c236.x8top.net.
MD5:
ae928765fc4f309e3cbe29b39c2a5e91

SHA-1:
109911c64455ed7084c530eb90edfcc52e4381c6

SHA-256:
8d5332f1d7b6313427acb55d6dbd6d4457989cbff1908c64d4ce872fde48c9ba

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:24:57 AM UTC  (today)

File size:
17.7 MB (18,548,960 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\zalo_123.exe

File PE Metadata
Compilation timestamp:
2/25/2012 2:19:54 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:65Jl2I/H4aBFMNbZLIt+wigKMcFU1lle3/KYF6Ce:65Jl2sBFMNbZLw+jcR1beJre

Entry address:
0x3883

Entry point:
85, F2, F6, D8, 4E, 74, 06, 89, C6, 4F, C6, C2, 94, 13, D5, 8D, 01, B2, 68, F7, C2, 14, 60, 6B, 0C, 8D, 08, 3B, D0, 78, 08, 84, D7, 8D, 35, 3D, DE, 5B, 37, 0F, AF, C9, C6, C0, 5B, FF, CB, 3A, CB, E8, 68, 00, 00, 00, 8A, EE, 8A, EF, 68, EE, 84, 0B, 00, 5F, C7, C5, A2, 5D, 79, B0, 81, F7, 92, 0B, 00, 00, 0F, BF, EF, 8B, C7, 2D, EF, 09, 00, 00, 8D, 1D, 41, 70, 4D, B6, BB, F1, 5D, 0A, FD, 0F, BE, EB, 8D, 10, C6, C3, 8C, 81, EA, 68, 81, 0B, 00, 81, F9, EC, FB, 00, 00, 72, 03, 0F, AF, DB, 81, EA, 6F, FF, FF, FF...
 
[+]

Entropy:
7.9985  (probably packed)

Code size:
27.5 KB (28,160 bytes)

The file zalo_123.exe has been seen being distributed by the following URL.

Scan zalo_123.exe - Powered by Reason Core Security