C9.exe

Continent of The Ninth

Webzen

This is a setup program which is used to install the application. The file has been seen being downloaded from patch.c9.in.th.
Publisher:
Webzen

Product:
Continent of The Ninth

Version:
2, 0, 0, 0

MD5:
aacccfde3fe61078d573c4bf5b24ebec

SHA-1:
67605fb40b01e462bb4bdcaf3a3925142bfee2be

SHA-256:
e395f61bcb12335afe7a0f2dc2200599a348da767783d8f9d60aa53ffa409674

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
6/15/2024 9:59:34 PM UTC  (today)

File size:
11.9 MB (12,506,112 bytes)

Product version:
2, 0, 0, 0

Copyright:
Copyright (C) Webzen 2008

Original file name:
C9.exe

File type:
Executable application (Win32 EXE)

Language:
Korean (Korea)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\c9.exe

File PE Metadata
Compilation timestamp:
4/5/2016 5:03:38 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:smQaj4bq2UmUVCcaTDkrdGUWEXyPWVID+JINoJDc179R9oILgwPCQ23:BQTFU4NkQFjPWVuMgx9R9pLguCl

Entry address:
0x64010F

Entry point:
E9, E1, D7, A7, FF, A1, A1, CF, 6E, 0A, CC, 2F, C5, 40, 8B, 46, 3B, 87, C9, 1F, B5, E1, AB, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 64, 32, C7, C0, FC, EC, 2E, 2D, 83, 9E, 16, A2, E4, 2C, 60, 7E, A9, 2B, ED, 01, B7, CD, A6, 75, 19, 20, E6, 4C, 8B, C9, DB, FF, 30, 1E, D3, E3, E9, 02, C6, AD, C4, 25, CE, 33, 14, BB, DD, F0, 0C, 1D, ED, 2C, 98, 0D, F7, A3, AE, CF, C5, DA, 88, 35, D9, C0, 62, CA, 0C, F0, 2C, 52, 09, BE, 1C, 34, 36, FF, A7, 96, A4, 27, CE, 5A, F0, 9C, EB, AB, 60, CE, 21, 43, BD, A2, D2, DA, 76...
 
[+]

Entropy:
7.8956

Packer / compiler:
Xtreme-Protector v1.05

Code size:
18 MB (18,891,776 bytes)

The file C9.exe has been seen being distributed by the following URL.

Scan C9.exe - Powered by Reason Core Security