mywifi.exe

Who Is On My Wifi

IO3O LLC

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from download002.fshare.vn and multiple other hosts.
Publisher:
IO3O LLC   (signed by IO3O LLC)

Product:
Who Is On My Wifi

Description:
Who Is On My Wifi Setup

MD5:
90cff398cc2679dd881189c6cce1b29c

SHA-1:
ad7d632761562c316dfab636e5a93e2f72e342b0

SHA-256:
2ed7a6ffc9e7b8c48d075fe60b87c5163c5d5ae15383a644c5d46efe0360e236

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:35:01 AM UTC  (today)

File size:
2.3 MB (2,442,208 bytes)

Product version:
3.0.2

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\mywifi.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/25/2013 1:00:00 AM

Valid to:
1/26/2016 12:59:59 AM

Subject:
CN=IO3O LLC, O=IO3O LLC, STREET=704 W. Sheridan, L=Oklahoma City, S=OK, PostalCode=73102, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D6EB4B8F1DF86E2B4424120FD554F9FD

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:EvLS1lz5+ZMkMWxQYemNpbHcVmWRdZsz0+gKUbIZ7MwNEVx:wE95+ZBMWeYtDHcoWbZM0+V8ICw6

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Code size:
37 KB (37,888 bytes)

The file mywifi.exe has been seen being distributed by the following 15 URLs.

http://download002.fshare.vn/dl/.../mywifi- Vforum.vn.exe

http://download002.fshare.vn/dl/.../mywifi- Vforum.vn.exe

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=537fbf28b7536e01436a623c66f370da7663aa97f213f457e137ca65924a164c622079f8e76d2fb11522f7fa0d2e0c53443212dfbaf54e65765cc34ef481d89fc69cf487d74896fdfb223706f9108261c7098727af531f619e1834ce1c3b16e1f83ea365574b359dd8defa781a2f9a35e461a2161d4d6e250a6e7b9fc7b8b67db588&url=0b3da36fa30172185e33366174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e33366174fd75853636b390ad53fc55a0&jump_type=download&file=mywifi-vforum.vn.exe

http://dw8.en.uptodown.com/dl/1417084132/.../who-is-on-my-wifi-3-0-2-en-win.exe

http://www.ranchmetabits.com/sLc3fg5be5AylQDe34a17bHHWa4bUj9EY2Z0MQtUvX1vvx2RiH8We_ENmcfjWotOr5NhTbpSB_egBkoRqvnpxj2c8pTeNF_5BYsZFTl5Rze3d7Kp4z1c0Wj8qyLIs8ULjQmzYcr0pUi7Oa3dBLK_0Tqim21oLyNhUprWoFjbVGdOjaaAW1HLVykFgf4MBHldRMP6CuhUR6YY2s727zB8csvZoUTknA==-GxkDAGSwbfR8cEEaT8BZyMhRH8neCIGJHLC3xRDzSey9ceDJGiM_i8DE8dKnbbZGS0vwHktHXlzJZ4VQJzPobwYL1cWdYIqDjyg7laNHW5D2LJNN1SgPfLJW5JP7R2T0dp3G5rte7bxLe_HOMVwOPLqotGDdovrS8e6GsREhX ikdzXPupoRCW_bg17nU28f6YkEAmk5 nU722zSPZQoluZKvTUCEadYM4rA9AfTYxY1AgC yjEOnjO brfzTl2f5cU9jjXNWRj11Dsan1EhMqU2sq1MS8vnM0nM4AeBbxV5R8dYMijO6dMLipT 4RdKSziLpmrn2GNtraSpeZGxbZrSAJeF_jI2QPJjluLNUoJLJrGcLZOYB9dO 4GxvMZDz_z0LYPORKnSExN7wUBp6vXX63lKM95aqLOLJiXQdIDAnamwo YQdrbayvl2bPD0Mq0dJOnc 4R vJf5YDxsWTIjnxZyL5Pvvdyn76N0q6fQPlm4pR6mb_fMy0GHypzyL9nb3OOebe7rhaGCFMCjTBfKSoyOdctKFBCsaSh8vkw2EYZ3vQ9aNY_qfxiojHWI4L6dlenrYrN1rmsbjA6WJVrgzBV69ZOTRwdGvPhTcm7ymxxqxgyV0fgluKovEWVqP0kYGs97FUHK2yl7I8nbDzaed2zDyfdpyAUtqrWXMt_SvqZL23d3a0F5_GpWnwAFxPMJ6bPM64thPq_fvw9GFUXNJFkrdO3SUYR_mAU7G7

http://s6.picofile.com/d/.../mywifi.exe

Scan mywifi.exe - Powered by Reason Core Security