webcomponents.exe

Web Components

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from 192.168.100.200 and multiple other hosts.
Product:
Web Components

Description:
Web Components Setup

Version:
3.0.5.43

MD5:
ee0fcf10d07416d77c2e5c1a6e6a6c0f

SHA-1:
0d1ecd9092641263af2b30474c45b13a69db9292

SHA-256:
2599beaa4a3e863af0aa27e1fb2620d7e4ee7c6236a5bbe626f320c0c458b2d1

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/4/2024 11:49:28 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Slugin.A
7.11.30.172

File size:
1.8 MB (1,859,352 bytes)

Product version:
3.0.5.43

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\webcomponents.exe

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:YRcOjSmcq3r95+0xNCii9NI+rCoBNswLIlm4yn5ZA4:YRccLZ5+0HCpXIU83YZn

Entry address:
0x9978

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 22, 97, FF, FF, E8, F1, A8, FF, FF, E8, 1C, CB, FF, FF, E8, 63, CB, FF, FF, E8, 2E, F3, FF, FF, E8, 95, F4, FF, FF, 33, C0, 55, 68, 2B, A0, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, F4, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 22, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 28, D1, FF, FF, 8B, 55, F0, B8, E0, CD, 40, 00, E8, B7, 97, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E0, CD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.9950

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36.5 KB (37,376 bytes)

The file webcomponents.exe has been seen being distributed by the following 50 URLs.

http://192.168.100.200:8002/.../WebComponents.exe

http://46.148.78.34/.../WebComponents.exe

http://10.15.4.207/.../WebComponents.exe

http://89.171.167.86:89/.../WebComponents.exe

http://192.168.104.98:85/.../WebComponents.exe

http://192.168.1.100/.../WebComponents.exe

http://192.168.1.250/.../WebComponents.exe

http://192.168.1.50/.../WebComponents.exe

http://192.168.1.90/.../WebComponents.exe

http://192.168.2.199/.../WebComponents.exe

http://toyotacy.fujiko.biz:8088/.../WebComponents.exe

http://2.226.201.158/.../WebComponents.exe

http://192.168.1.2:8050/.../WebComponents.exe

http://175.137.229.200/.../WebComponents.exe

http://79.110.197.123:81/.../WebComponents.exe

http://192.168.1.223/.../WebComponents.exe

http://galaxyd.dvrdns.org/.../WebComponents.exe

http://boomacapulco.a.epcomcctv.com/.../WebComponents.exe

http://192.168.1.10/.../WebComponents.exe

http://nasakramp.dyndns.org:8181/.../WebComponents.exe

http://mpintersafe.fujiko.biz:81/.../WebComponents.exe

http://192.168.1.2:8080/.../WebComponents.exe

http://192.168.3.18/.../WebComponents.exe

http://192.168.1.200:8081/.../WebComponents.exe

http://fruteriaemilio.cctvddns.net:90/.../WebComponents.exe

http://109.190.251.219/.../WebComponents.exe

http://110.171.72.157:100/.../WebComponents.exe

http://192.168.1.210:88/.../WebComponents.exe

http://175.143.37.146/.../WebComponents.exe

http://192.168.1.101/.../WebComponents.exe

Latest 30 of 55 download URLs

Scan webcomponents.exe - Powered by Reason Core Security