dat0420.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from 113.171.224.175 and multiple other hosts.
MD5:
cd1390edf2da7b5166bcbbbab6b08b58

SHA-1:
06e2fc6153ab1aad5520900f63b8a4f195b3db7d

SHA-256:
0436b25b44a164407450edde40b83923d64fa464156fea0db0ee0c306c0e7eaa

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/6/2024 3:26:44 AM UTC  (today)

File size:
18.4 MB (19,324,170 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\dat0420.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
393216:qA9sMOvVqEJxigvgCUuWrFiZ/sViGXNumWQ4y1jqTk6BcLMU0LPTBxn:aMOvVnJxigYnFeYHtnuBcYU0LPtJ

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 59, A5, C1, 6B, CB, 99, 86, 7C, 5B, 00, 00, 00, 00, 7D, 00, 00, 00, 00, 00, 00, 00, 19, 50, 7C, A6, 00, 40, 57, 18, EA, C7, F9, 46, 17, 95, C1, C4, 3A, E5, 1D, 51, 05, 24, 2F, C5, F4, 90, 14, BB, 23, 05, 59, A5, AB, F9, 49, BB, 87, 18, 6A, 38, 1B, 8A, EA, BD, 23, D4, AC, D9, EB, 43, AE, CB, D3, FA, 49, 2D, 2B, 0D, 82, BF, 98, 69, D0, E0, 40, 37, AD, A6, 50, FB, FB, B7, EF, 22, CA, A9, 0A, 18, E9, 47, 4D, CD, 9A, F5, EB, DF, F9, B4, 23, 46, 8A, 92, A2, CD, A5, 5E, 10, 42, 4A, C2...
 
[+]

The file dat0420.exe has been seen being distributed by the following 4 URLs.

http://113.171.224.175/.../dat0420.exe

http://113.171.224.245/.../dat0420.exe

http://113.171.224.213/.../dat0420.exe

Scan dat0420.exe - Powered by Reason Core Security