InstFonts.exe

InstFonts

Cabsoftware

Publisher:
RedFox KOREA  (signed by Cabsoftware)

Product:
InstFonts

Version:
1.00

MD5:
6d42dbd828abd9b2edc25441aa8b00d7

SHA-1:
c2e372f0c31a70ad84986dccaaa2649f86c05ab9

SHA-256:
2ed3f60443e46afa6a7163e09f537f4ca8aa04d66eef10105a6c8a82496bf3e1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 12:13:55 PM UTC  (today)

File size:
29.4 KB (30,064 bytes)

Product version:
1.00

Original file name:
InstFonts.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\instfonts.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/1/2009 9:00:00 AM

Valid to:
6/24/2012 8:59:59 AM

Subject:
CN=Cabsoftware, OU=Developement, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Cabsoftware, L=Seongnam, S=Kyounggi, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
09883B59F556B29AE7270E385258DD12

File PE Metadata
Compilation timestamp:
6/8/2009 5:14:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
384:RDLx3+mmwY7nlXB4ByjQ4GDG4G4BElFLYJLWv87dbIbJM:33+mmvpXB48K78lgLbdbsK

Entry address:
0x13A8

Entry point:
68, 74, 15, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, EF, 12, 67, 81, 91, 41, 33, 4B, B5, 55, 6A, 66, 49, BE, 53, 0D, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, B7, 00, 00, 00, 49, 6E, 73, 74, 46, 6F, 6E, 74, 73, 00, DF, 5C, C1, F5, B8, ED, 00, 00, 00, 00, 01, 00, 03, 00, 00, 19, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, E4, 19, 40, 00, 38, 40, 40, 00, 00, 00, 00, 00, 40, 6A, 5F, 0D, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.5651

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
12 KB (12,288 bytes)

Scan InstFonts.exe - Powered by Reason Core Security