folderclone.exe

FolderClone

Salty Brine Software

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘folderclone’.
Publisher:
Salty Brine Software  (signed and verified)

Product:
FolderClone

Version:
2.01.0001

MD5:
5bb321cd3dac5772a90bf3bb28004f5b

SHA-1:
8870ecd111a30c6b687d0e43adfc305d083ea77d

SHA-256:
ecbb258e1b73811e9c1b079c648ddaf6f5c277eb37c14e61c83d9ff9f4462c3f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 9:44:57 AM UTC  (today)

File size:
1.2 MB (1,229,528 bytes)

Product version:
2.01.0001

Original file name:
folderclonepro.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\folderclone\folderclone.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/11/2014 8:00:00 AM

Valid to:
8/11/2016 7:59:59 AM

Subject:
CN=Salty Brine Software, OU=Salty Brine Software, O=Salty Brine Software, STREET=PO Box 353326, STREET=Palm Coast, L=Art Araya, S=FL, PostalCode=32135, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A553424F4B641712FEBE04340D6B73FE

File PE Metadata
Compilation timestamp:
2/18/2015 8:19:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:/qfQcjBJIkRxjrh3hdcqJM2Ln3w4BeB5Mk100wUkq6fFrkkwVi:/MfBJ/xjVRtBn3w4Be/W0NH6trkk9

Entry address:
0x46E469

Entry point:
E8, 3B, FF, FF, FF, 05, 8D, 20, 00, 00, FF, E0, E8, 2F, FF, FF, FF, 05, 5F, 25, 00, 00, FF, E0, E8, 04, 00, 00, 00, FF, FF, FF, FF, 5E, C3, 00, 8A, D9, EC, 88, DD, A0, BE, 45, 20, C3, CA, 45, BF, 79, DF, 92, 8C, 95, 10, 5D, 1C, BA, A2, 7B, 36, 4B, 2C, 69, 59, 23, C4, E4, 25, 74, CC, A7, DE, 7D, DF, 8B, AD, 2A, 2B, 62, 78, 2B, 8A, A9, BE, 43, 84, B4, 7E, FB, D6, C4, 66, 5E, 6D, 7F, C0, CA, B0, 88, 60, 39, 31, 69, 8A, 80, D3, 98, 02, B3, 0F, BD, F0, A9, 3D, 90, 49, 09, FE, 09, 33, 12, 7E, 47, 1C, 09, C2, 97...
 
[+]

Entropy:
7.9866  (probably packed)

Code size:
2.9 MB (3,063,808 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
folderclone

Command:
C:\Program Files\folderclone\folderclone.exe


Scan folderclone.exe - Powered by Reason Core Security