bolehvpn.exe

BolehVPN Sdn Bhd

It runs as a scheduled task under the Windows Task Scheduler named BolehVPN triggered to execute each time a user logs in.
Publisher:
BolehVPN Sdn Bhd  (signed and verified)

MD5:
b265503876d34f15c8ce7a30c9b84617

SHA-1:
48bd5c444091fe7da0853ab1d0b732f4e851ba4c

SHA-256:
abd05374358951a7da5e22df2f5355f36e0404835f30cce96a0dfef247313d95

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 12:14:51 AM UTC  (today)

File size:
801.7 KB (820,912 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\bolehvpn\bolehvpn.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/4/2012 4:00:00 PM

Valid to:
12/5/2014 3:59:59 PM

Subject:
CN=BolehVPN Sdn Bhd, O=BolehVPN Sdn Bhd, STREET="Lane Building, 29 Kai Joo Lane,", L=Kuching, S=Sarawak, PostalCode=93000, C=MY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
011D404181784E8DB3A4C994C6A4501B

File PE Metadata
Compilation timestamp:
12/8/2013 5:21:28 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:Xbt+w8hVnpRvdrEs+GJ0pJB64Mf3ZYjQwu7ftU0R79G:Xbt+w8bpRV1JUPMfp3jftU07M

Entry address:
0x25DEE

Entry point:
E8, 95, 04, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, E8, E8, 4B, 00, 89, 0D, E4, E8, 4B, 00, 89, 15, E0, E8, 4B, 00, 89, 1D, DC, E8, 4B, 00, 89, 35, D8, E8, 4B, 00, 89, 3D, D4, E8, 4B, 00, 66, 8C, 15, 00, E9, 4B, 00, 66, 8C, 0D, F4, E8, 4B, 00, 66, 8C, 1D, D0, E8, 4B, 00, 66, 8C, 05, CC, E8, 4B, 00, 66, 8C, 25, C8, E8, 4B, 00, 66, 8C, 2D, C4, E8, 4B, 00, 9C, 8F, 05, F8, E8, 4B, 00, 8B, 45, 00, A3, EC, E8, 4B, 00, 8B, 45, 04, A3, F0, E8, 4B, 00, 8D, 45, 08, A3, FC, E8, 4B...
 
[+]

Entropy:
7.6233

Code size:
171.5 KB (175,616 bytes)

Scheduled Task
Task name:
BolehVPN

Trigger:
Logon (Runs on logon)


Scan bolehvpn.exe - Powered by Reason Core Security