closeanonymity.exe

Security Stronghold LLC

The application closeanonymity.exe by Security Stronghold has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Security Stronghold LLC  (signed and verified)

MD5:
9e9576a77513d1edfc0b97ee424bb559

SHA-1:
6358aa5e3db22b896425ce056ac53375d7c18aa1

SHA-256:
68567f09f810240837ec0585c4790f6b659134dec181f2fbe3eb2f589067efb5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/16/2024 7:21:42 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.6.19.4

File size:
31.9 KB (32,696 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/10/2011 10:49:57 AM

Valid to:
10/10/2012 10:49:57 AM

Subject:
E=manager@securitystronghold.com, CN=Security Stronghold LLC, O=Security Stronghold LLC, L=Astrakhan, S=Astrakhan region, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112178C42A18008AB27616B3F5140692C337

File PE Metadata
Compilation timestamp:
4/5/2012 12:40:24 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
384:O7kvN6cdP2JwRpsVxVNeAN3InvZCBb0HdJPWuqxeXEb1d/Db1Otm4x+HIOHLIKk0:OIv152Mw3puvZ59JJE5dZqaodD0

Entry address:
0x60D4

Entry point:
55, 8B, EC, 83, C4, F0, B8, EC, 42, 40, 00, E8, 64, DB, FF, FF, 6A, 00, 68, 1C, 61, 40, 00, E8, 8C, E1, FF, FF, 6A, 00, 6A, 00, 6A, 10, 50, E8, 88, E1, FF, FF, 6A, 00, 68, 48, 61, 40, 00, E8, 74, E1, FF, FF, 6A, 00, 6A, 00, 6A, 10, 50, E8, 70, E1, FF, FF, E8, 93, D5, FF, FF, 00, 00, 00, 54, 00, 56, 00, 49, 00, 50, 00, 41, 00, 6E, 00, 6F, 00, 6E, 00, 79, 00, 6D, 00, 69, 00, 74, 00, 79, 00, 4D, 00, 61, 00, 69, 00, 6E, 00, 46, 00, 6F, 00, 72, 00, 6D, 00, 00, 00, 54, 00, 56, 00, 49, 00, 50, 00, 41, 00, 6E, 00...
 
[+]

Entropy:
5.9243

Developed / compiled with:
Microsoft Visual C++

Code size:
19 KB (19,456 bytes)

Remove closeanonymity.exe - Powered by Reason Core Security