3aff458361ee21d67f4cc92e90854c6c.exe

爱思助手

深圳市为爱普信息技术有限公司

Publisher:

Product:
爱思助手

Description:
爱思助手 5.0

Version:
5, 7, 2, 0

MD5:
3aff458361ee21d67f4cc92e90854c6c

SHA-1:
e8d9a74f4073de07df681b0a28c86ea58d834668

SHA-256:
eb7822e9c6932673c34d9c0a43313ffed84e58b457612fba2f247a5e12f1e662

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/18/2024 8:52:57 PM UTC  (today)

File size:
3.1 MB (3,246,448 bytes)

Product version:
5, 7, 2, 0

Copyright:
Copyright (C) 2014

Original file name:
i4tools

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\3aff458361ee21d67f4cc92e90854c6c.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/26/2016 3:20:32 PM

Valid to:
6/20/2016 4:09:33 PM

Subject:
CN=深圳市为爱普信息技术有限公司, OU=IT Dept., O=深圳市为爱普信息技术有限公司, L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121489EB7D6639A5B0CB949A9C319C024FE

File PE Metadata
Compilation timestamp:
6/15/2016 8:21:27 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:gjqryVIZSc/D3tUy4+zlr+YC1cRxMMMMMMMMMMMMMMMMMMMMG8K:cq7hUy4+DK

Entry address:
0x1AF917

Entry point:
E8, E0, 04, 00, 00, E9, D7, FC, FF, FF, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 0C, F1, 5A, 00, 68, 4C, B0, 65, 00, E8, 51, 05, 00, 00, 83, C4, 18, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 3A, 05, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 24, 05, 00, 00, FF, 25, CC, AF, 5D, 00, FF, 25, C8, AF, 5D, 00, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, D4, AE, 5D, 00, FF...
 
[+]

Entropy:
6.2611

Code size:
1.8 MB (1,936,384 bytes)

The file 3aff458361ee21d67f4cc92e90854c6c.exe has been seen being distributed by the following URL.

http://d.updater.i4.cn/i4toolupdate5/i4tools/.../3AFF458361EE21D67F4CC92E90854C6C.exe

Scan 3aff458361ee21d67f4cc92e90854c6c.exe - Powered by Reason Core Security