picexa.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from 113.171.224.206 and multiple other hosts.
MD5:
f7e3b32572ba1aee13cc02b34c7e16ea

SHA-1:
95fb056273b1322b9423a7fa0e92cc959bd1354e

SHA-256:
a7fcccdf70b5dfc9e163ac91dda294824476f023069dfab2b4c0ca8dc5fc45f8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/27/2024 12:34:16 AM UTC  (today)

File size:
1.2 MB (1,282,450 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\c5q0go3a\picexa.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
24576:Hcnd+M9+yN1sx3u1+r9H1Bd/Dgso+vb6NY2LX0NdF7REATVeA0nb:snwynOuW/D0RNXENH767Znb

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, 03, F6, 7C, D6, 14, CB, 49, 00, 00, 00, 00, 00, 7E, 00, 00, 00, 00, 00, 00, 00, CC, 44, 29, 3C, BB, C1, 41, BA, 59, 07, 00, 40, 56, 18, E2, A0, CC, 05, CC, 82, 28, 88, 79, FF, 24, F1, 52, 84, 9D, 8A, 6C, E8, ED, BA, 55, C6, 7C, EA, DA, 64, C9, 61, D0, 18, F7, AF, 75, C4, F1, 3F, AE, 71, E8, E8, F5, 3C, 9B, CF, 80, 0A, 74, A8, 2E, D2, E9, 09, 6C, 9F, CA, 5E, 6F, 95, 29, CF, FF, 25, 8B, D0, 73, 55, B4, F1, 31, 3D, 08, 8D, 25, 68, BC, 4E, 17, 63, 44, 68, 9E, 26, 9D, 3D, 58, DE...
 
[+]

The file picexa.exe has been seen being distributed by the following 12 URLs.

http://113.171.224.206/.../picexa.exe

http://www.downosul.com/Public/softs/lim2/9283/.../picexa.exe

http://103.18.2.109/files/2104000000039A4A/www.downxkyah.com/Public/softs/lim2/9283/.../picexa.exe

http://113.171.224.211/.../picexa.exe

http://113.171.224.170/.../picexa.exe

Scan picexa.exe - Powered by Reason Core Security