aqfcarrier_1_0_1_12.exe

永久不滅プラス Toolbar

Credit Saison Co., Ltd.

Publisher:
Credit Saison Co.,Ltd.  (signed by Credit Saison Co., Ltd.)

Product:
永久不滅プラス Toolbar

Description:
永久不滅プラス Toolbar Agent Module

Version:
1, 0, 1, 12

MD5:
5c38e97a19c7387b0eb07d4539726990

SHA-1:
03b50eea57acf81c39e07779b65a84d2fcaf5630

SHA-256:
3a8d6d1deb276d8a3082823f926fd5236a1dc26ddd225a106121bbe557f1feea

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 9:37:14 PM UTC  (today)

File size:
203.8 KB (208,680 bytes)

Product version:
1, 0, 1, 12

Copyright:
Credit Saison Co.,Ltd.

Original file name:
JPToolbarCarrier.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\永久不滅プラス\toolbar\aqfcarrier_1_0_1_12.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/17/2013 9:00:00 AM

Valid to:
12/18/2018 8:59:59 AM

Subject:
CN="Credit Saison Co., Ltd.", O="Credit Saison Co., Ltd.", STREET="3-1-1, Higashiikebukuro", L=Toshima-ku, S=Tokyo, PostalCode=170-6073, C=JP

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F4C4A717BE8FB8BFD13D7C843C663311

File PE Metadata
Compilation timestamp:
12/22/2015 11:04:48 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:OLyEPI8F8QFo9Ee+kfIYMXkGa65YQL6XZGZizySFASKtLDnBHp+UUleb:zEPR8phIYo/aCL6XsZuySeLlKeb

Entry address:
0x1305C

Entry point:
E8, A5, 96, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, D0, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 66, 8B, 4D, 0C, 48, 48, 3B, C2, 74, 05, 66, 39, 08, 75, F5, 66, 39, 08, 74, 02, 33, C0, 5D, C3, 8B, FF, 55, 8B, EC, 33, C0, 39, 45, 0C, 76, 11, 8B, 4D, 08, 66, 83, 39, 00, 74, 08, 40, 41, 41, 3B, 45, 0C, 72, F2, 5D, C3, 8B, FF, 55, 8B, EC, 51, E8, FC, 4C, 00, 00, 8B, 4D, 08, 89, 45, FC, 85, C9, 75, 03, 8B, 48, 1C, 0F, B7, 11, 56, 57, 66, 85, D2, 74, 30, 8B, 45, 0C, 0F, B7, 00, 8B, 7D, 0C...
 
[+]

Entropy:
6.4705

Packer / compiler:
PEQuake V0.06

Code size:
145 KB (148,480 bytes)

The file aqfcarrier_1_0_1_12.exe has been seen being distributed by the following URL.

Scan aqfcarrier_1_0_1_12.exe - Powered by Reason Core Security