hantoolagent.exe

한툴 2013

주식회사 캔싱

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘HantoolAgent’.
Publisher:
(주)캔싱  (signed by 주식회사 캔싱)

Product:
한툴 2013

Description:
Hantool Agent

Version:
3, 0, 0, 1

MD5:
bdda2abb39a2e1923a11ef651fe25796

SHA-1:
0e38b06f7f91220fb9cfa91146ba5dc359bc1b7e

SHA-256:
dda1c4bf4b114f682fc1765db690851c2dd60f0440baaf46d7890dcde629383f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/18/2024 4:39:15 AM UTC  (today)

File size:
528.1 KB (540,776 bytes)

Product version:
3, 0, 0, 1

Copyright:
Copyright (c) - (주)캔싱 2013

Original file name:
hantoolagent.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\hantoolagent\hantoolagent.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/29/2013 9:00:00 AM

Valid to:
1/30/2014 8:59:59 AM

Subject:
CN=주식회사 캔싱, OU=Dev. Team, O=주식회사 캔싱, L=Yongsan-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2EF4183EC9DA75A2EB617C46B5E696EF

File PE Metadata
Compilation timestamp:
8/9/2013 3:54:57 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:JzvAAD37AR6cqwUeOXATwDlwRH7vKljZ1gFwG69Kuhq:JzvA2LAewU0slwRejZSj6zhq

Entry address:
0x2DEF0

Entry point:
8B, FF, 55, 8B, EC, E8, E6, 87, 01, 00, E8, 11, 00, 00, 00, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 6A, FE, 68, 40, 11, 47, 00, 68, 20, F5, 42, 00, 64, A1, 00, 00, 00, 00, 50, 83, C4, 94, 53, 56, 57, A1, E0, 62, 47, 00, 31, 45, F8, 33, C5, 50, 8D, 45, F0, 64, A3, 00, 00, 00, 00, 89, 65, E8, C7, 45, 90, 00, 00, 00, 00, C7, 45, FC, 00, 00, 00, 00, 8D, 45, A0, 50, FF, 15, 38, F2, 45, 00, C7, 45, FC, FE, FF, FF, FF, EB, 26, B8, 01, 00, 00, 00, C3, 8B, 65, E8, C7...
 
[+]

Entropy:
6.3367

Code size:
372.5 KB (381,440 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
HantoolAgent

Command:
C:\Program Files\hantoolagent\hantoolagent.exe


Scan hantoolagent.exe - Powered by Reason Core Security