ic-0.3dad521fe77494.exe

Xin Zhou

The executable ic-0.3dad521fe77494.exe has been detected as malware by 1 anti-virus scanner. While running, it connects to the Internet address server-52-84-246-75.sfo20.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
Xin Zhou  (signed and verified)

MD5:
d983f3a0adfd0d805d4e00b39ccdaacf

SHA-1:
1037f1d6bb68d6731eae367b897d0e059cd6ca8c

SHA-256:
8e1bf60abaa38299080416679949eb7fee9f4bf63b705baa6d02fd2818702d42

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
5/9/2025 9:01:24 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.25.15

File size:
412.5 KB (422,448 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ic-0.3dad521fe77494.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
1/17/2017 1:00:00 AM

Valid to:
3/23/2017 12:59:59 AM

Subject:
CN=Xin Zhou, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
65A50AC1DC609167928FF03D2E9DB9B7

File PE Metadata
Compilation timestamp:
2/13/2017 2:46:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x8A03

Entry point:
E8, E6, B1, FF, FF, E9, BA, 2C, 00, 00, 55, 8B, EC, 83, 3D, B8, 65, 46, 00, 00, 75, 11, 8B, 4D, 08, A1, A0, 58, 46, 00, 0F, B7, 04, 48, 83, E0, 04, 5D, C3, 6A, 00, FF, 75, 08, E8, F9, E0, FF, FF, 59, 59, 5D, C3, 55, 8B, EC, 6A, 00, 6A, 01, FF, 75, 08, E8, F4, 30, 00, 00, 83, C4, 0C, 5D, C3, 6A, 64, 68, 08, 41, 46, 00, E8, 18, 32, 00, 00, 6A, 0B, E8, 0C, A9, FF, FF, 59, 33, DB, 89, 5D, FC, 6A, 40, 6A, 20, 5F, 57, E8, 0D, A8, FF, FF, 59, 59, 8B, C8, 89, 4D, DC, 85, C9, 75, 1B, 6A, FE, 8D, 45, F0, 50, 68, 00...
 
[+]

Code size:
373.5 KB (382,464 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-52-84-246-17.sfo20.r.cloudfront.net  (52.84.246.17:80)

TCP (HTTP):
Connects to server-52-84-246-75.sfo20.r.cloudfront.net  (52.84.246.75:80)

TCP (HTTP):
Connects to server-52-84-246-4.sfo20.r.cloudfront.net  (52.84.246.4:80)

TCP (HTTP):
Connects to server-54-192-14-34.ams1.r.cloudfront.net  (54.192.14.34:80)

TCP (HTTP):
Connects to server-54-192-14-158.ams1.r.cloudfront.net  (54.192.14.158:80)

TCP (HTTP):
Connects to server-54-192-14-114.ams1.r.cloudfront.net  (54.192.14.114:80)

TCP (HTTP):
Connects to server-54-230-216-242.mrs50.r.cloudfront.net  (54.230.216.242:80)

TCP (HTTP):
Connects to server-54-239-132-94.sfo9.r.cloudfront.net  (54.239.132.94:80)

TCP (HTTP):
Connects to server-54-230-216-106.mrs50.r.cloudfront.net  (54.230.216.106:80)

TCP (HTTP):
Connects to server-54-230-216-30.mrs50.r.cloudfront.net  (54.230.216.30:80)

TCP (HTTP):
Connects to server-54-230-216-181.mrs50.r.cloudfront.net  (54.230.216.181:80)

TCP (HTTP):
Connects to server-54-230-187-110.cdg51.r.cloudfront.net  (54.230.187.110:80)

TCP (HTTP):
Connects to server-54-192-230-51.waw50.r.cloudfront.net  (54.192.230.51:80)

TCP (HTTP):
Connects to server-54-230-216-44.mrs50.r.cloudfront.net  (54.230.216.44:80)

TCP (HTTP):
Connects to server-54-230-216-168.mrs50.r.cloudfront.net  (54.230.216.168:80)

TCP (HTTP):
Connects to server-54-230-216-108.mrs50.r.cloudfront.net  (54.230.216.108:80)

TCP (HTTP):
Connects to server-54-230-187-8.cdg51.r.cloudfront.net  (54.230.187.8:80)

TCP (HTTP):
Connects to server-54-230-187-17.cdg51.r.cloudfront.net  (54.230.187.17:80)

TCP (HTTP):
Connects to server-54-230-187-46.cdg51.r.cloudfront.net  (54.230.187.46:80)

TCP (HTTP):
Connects to server-54-230-187-23.cdg51.r.cloudfront.net  (54.230.187.23:80)

Remove ic-0.3dad521fe77494.exe - Powered by Reason Core Security