wc06_pcweb.exe

The program is a setup application that uses the WinZip SFX installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
MD5:
31ee5df8c26e2331c40c30d31eb210e3

SHA-1:
f30ba6585e59b7c2bf46f9064b869588b622c0aa

SHA-256:
e1a3255ccb100c447d0e7e753e1bddb58461eabf7890b1dcee2fbf52e00b9d53

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/14/2024 8:06:45 AM UTC  (today)

File size:
343.7 MB (360,390,144 bytes)

File type:
Executable application (Win32 EXE)

Installer:
WinZip SFX

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\wc06_pcweb.exe

File PE Metadata
Compilation timestamp:
1/9/2001 10:08:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.10

CTPH (ssdeep):
6291456:44O6+vSYP+zxKjlZj+xRiDBOzRikUnQlwTqun/BX5WOtZ7nY+Z//8AI:M6+vScw48RiNgRikcOS/BX5WwZ7X9

Entry address:
0x39D8

Entry point:
53, FF, 15, 50, 60, 40, 00, B3, 22, 38, 18, 74, 03, 80, C3, FE, 8A, 48, 01, 40, 33, D2, 3A, CA, 74, 0A, 3A, CB, 74, 06, 8A, 48, 01, 40, EB, F2, 38, 10, 74, 01, 40, 52, 50, 52, 52, FF, 15, 54, 60, 40, 00, 50, E8, 07, F8, FF, FF, 50, FF, 15, 58, 60, 40, 00, 5B, C3, 8B, 44, 24, 04, 8B, 40, 3C, 05, F8, 00, 00, 00, C3, 55, 8B, EC, 51, A1, 28, 84, 40, 00, 83, 0D, A0, 82, 40, 00, FF, 56, 33, F6, 39, 35, F8, 7D, 40, 00, 89, 35, D4, 83, 40, 00, 89, 35, 24, 84, 40, 00, A3, C4, 86, 40, 00, 75, 05, E8, 67, D8, FF, FF...
 
[+]

Entropy:
7.9992  (probably packed)

Code size:
18.5 KB (18,944 bytes)

The file wc06_pcweb.exe has been seen being distributed by the following 8 URLs.

http://dw.uptodown.com/dwn/sFAAqGWlhbARL29PRN3WfXY4Mw61VXPcL2hG_LK1oYknFZA9RbHZ2Pff4ajNs72nLzik7hGs1v629nXm7bAHU0SPBSHcev-HNyQcPd4q0ck2d7n9eb2WkCtPYpfyjJEE/q1TJLTCCodnPfkybhp80_gkXf0ShUNIaCc2nRO9FG6peUcZ2f5pupcHwgwRj0-uL9WuSOYtoDZXKVZVX_BNoBYTaAgHV1A66F0vUdrmIkcscxjFZROeBpm4za293VpQM/.../

https://dw.uptodown.com/dwn/PNla5pGS4ifD2ntDWVhHbPFQrqdIu_yDwZ-IG2KH8Uf5od80gHKoKGhwlScuYOCnG2jZc1Gylgn948hFraSKmlH3yCSvgS1_ffIorVQmv4KhgXOAtYlUqkIRUGofR6Up/9ALgaDEaDoel4vNckYSiAdqoHOtOSrfhHFNi686ZKnQZ7SSdHo5wepfp7ZBmo9SIeS4NfnWfUpm362d6m4MxNcdYQnopVqZJIEZw0uguLHtwrIrwImD6mt0Dp5rgxBwi/FHONSJK8axSmfzsMlQIDkuPqE3US-gO8UW1JF0U_kBBvLHqnG7Z_W360wa5eLNgmPLOWkukTO53tyATO7riSWQM1L8zfd_HxeE0wcwehlELakSNNAR0QFI6wJrOesLkl/.../

https://dw.uptodown.com/dwn/1s-lsHlV_b8jauNp3nljwGfcLV-xgSGQtgUOAw1IXx8fHWO_fbB2UVOlwSEBmKkViTZ3TykCzUfMbsHeCbIvGvSEMy_HD4V6QjA5NYj_IezuvZuZzzA_Th-602LbOaJ6/OtjzSGuuOri7KEI-J4suIlhZK3TCFW7qMI8_4n1wMWcMYaUyrdOWgFiCrX94DmGlE3b5qqwUsRNdBi5KnGD3Vlru2Eos8j8jAd6Bkqw0vcZbSD7PzHqYWHhPqlruQkWk/LmZnqgIXJ6o8QnMZSoiYC5tjavrN4LjFxpfXIY5ufPq5BVAaw8qtS48NBm4GeOxHqOhyZukfsFF9v4GP-erBX78ZKM_u8S6vfpd224xb2EAhJkY8K5jHbHTG9jlJ3v-p/.../

http://download.fileplanet.com/ftp1/.../WC06_pcweb.exe

https://dw.uptodown.com/dwn/2-HYF5chaGrBvaeZtd2UNCQEFo6n1mFGtPTrij7c7CfZkgfrM2ymioEaNBY-4qVXLo7rAXudDQkeEAEUu-RHY7wTJBrdOhWl1zU93RsBTtHlyFHEqKpWqYdJSNa8Qg58/owxHD8KuASzLaf6oufyokfu5gVOZET_FzNbDxUlt7CmqU8V1hPq5hSjSjAMtvvzJiJXpJucrvuzWmKCfYq5w5ZDTlFzpzUuBI1PcRePm1pEhbCxeCe9Lw7pgkuRJZtwE/.../

Scan wc06_pcweb.exe - Powered by Reason Core Security