installwizard101.exe

MD5:
c5f87f9f30a68b467c39559ef9753f3a

SHA-1:
44c5734184042c9262da686ab64f53f3ca3219cc

SHA-256:
7606828c47a9f058e935e8eac4cbdb0fbb16261a3db44005b564febc98909f71

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/20/2025 3:26:56 AM UTC  (today)

File size:
14.7 KB (15,053 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\installwizard101.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
384:TKR/c9btKwU4bjupQbtLSzvLMz+oWN9VYTQY:utmtKxN9s

Entry point:
3C, 68, 74, 6D, 6C, 20, 6C, 61, 6E, 67, 3D, 22, 65, 6E, 22, 3E, 0D, 0A, 3C, 68, 65, 61, 64, 3E, 0D, 0A, 20, 20, 20, 20, 3C, 21, 2D, 2D, 20, 57, 49, 53, 50, 72, 20, 73, 75, 70, 70, 6F, 72, 74, 20, 2D, 2D, 3E, 0D, 0A, 20, 20, 20, 20, 3C, 21, 2D, 2D, 0D, 0A, 20, 20, 20, 20, 3C, 3F, 78, 6D, 6C, 20, 76, 65, 72, 73, 69, 6F, 6E, 3D, 22, 31, 2E, 30, 22, 20, 65, 6E, 63, 6F, 64, 69, 6E, 67, 3D, 22, 55, 54, 46, 2D, 38, 22, 3F, 3E, 0D, 0A, 20, 20, 20, 20, 3C, 57, 49, 53, 50, 41, 63, 63, 65, 73, 73, 47, 61, 74, 65, 77...
 
[+]

Entropy:
5.7369

The file installwizard101.exe has been seen being distributed by the following URL.

Scan installwizard101.exe - Powered by Reason Core Security