anyplayer_hyper.exe

AnyPlayer Hyper

Korea Educational Broadcasting System

It runs as a separate (within the context of its own process) windows Service named “AnyPlayer_Hyper_Service”.
Publisher:
Neobsoft  (signed by Korea Educational Broadcasting System)

Product:
AnyPlayer Hyper

Version:
0.1.50.9011

MD5:
2eb3f3ca071579fbde2f76b9ddd5d245

SHA-1:
66c69633d635808a6d5370ee77fc7c990ce62a58

SHA-256:
ef34e24acba3ca7003cd385c10e168ae6f987013521e59a51838a8b402d88e09

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/8/2024 2:08:42 AM UTC  (today)

File size:
355.3 KB (363,856 bytes)

Product version:
0.1.50.9011

Copyright:
Copyright (C) 2006 - 2015 Neobsoft.

Original file name:
anyplayer_hyper.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ebs\anyplayer\anyplayer_hyper.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/26/2014 9:00:00 AM

Valid to:
5/26/2016 8:59:59 AM

Subject:
CN=Korea Educational Broadcasting System, O=Korea Educational Broadcasting System, L=Seocho-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3090F7BA8D64EA93EAC37E91D7223845

File PE Metadata
Compilation timestamp:
9/2/2015 3:44:32 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
6144:um+2mBo2/1D8sAtUxPAsbFir3QENBRxnrTjm+qMo+QlXGlqrP0Kt6aVy/AxzkOl0:Z+2mBo2/1D8sAtUxPAsbFir3QENBRxnV

Entry address:
0x2BFA3

Entry point:
E8, B1, D0, 00, 00, E9, 7B, FE, FF, FF, 55, 8B, EC, 83, EC, 24, 8D, 4D, DC, FF, 75, 08, E8, 3C, B8, FF, FF, 8B, 45, 10, 85, C0, 74, 05, 8B, 4D, 0C, 89, 08, 8B, 45, 0C, 53, 56, 57, 85, C0, 74, 11, 8B, 7D, 14, 85, FF, 74, 1F, 83, FF, 02, 7C, 05, 83, FF, 24, 7E, 15, E8, AC, 10, 00, 00, C7, 00, 16, 00, 00, 00, E8, 83, C6, FF, FF, E9, C1, 01, 00, 00, 8B, 7D, DC, 8D, 70, 01, 33, DB, 89, 5D, F4, 8A, 18, 83, 7F, 74, 01, 7E, 17, 8D, 45, DC, 50, 0F, B6, C3, 6A, 08, 50, E8, 7D, C8, 00, 00, 8B, 7D, DC, 83, C4, 0C, EB...
 
[+]

Entropy:
6.5974

Code size:
275 KB (281,600 bytes)

Service
Display name:
AnyPlayer_Hyper_Service

Description:
AnyPlayer Hyper Service

Type:
Win32OwnProcess


Scan anyplayer_hyper.exe - Powered by Reason Core Security