lanspy_setup.exe

LanTricks.com

This is a setup and installation application. This is installed with LanSpy. The file has been seen being downloaded from lanspy.software.informer.com and multiple other hosts.
Publisher:
LanTricks.com

Description:
LanSpy Setup

MD5:
42114d0f9e88ad76acaa0f145dabf923

SHA-1:
75453018ec3bc6bdcfb59caa6028ae23a3807182

SHA-256:
c71b545ad4819ec6528cbe9a22dec54f6107fc9c7157402c82ee77044f353d7d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 12:48:37 AM UTC  (today)

File size:
1.1 MB (1,143,724 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:A5LT730VhgI03HHl1HkTV5waCo8RBhCfajItclwg3QjfCu8u6LaF/X3YCnoLTu6:wL/Ei1Hcja9cmCggZ6+vxoLa6

Entry address:
0x9408

Entry point:
55, 8B, EC, 83, C4, B8, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, BC, 89, 45, B8, E8, BB, 9C, FF, FF, E8, F2, AE, FF, FF, E8, 35, D1, FF, FF, E8, 7C, D1, FF, FF, E8, FB, F5, FF, FF, BE, C4, BD, 40, 00, 33, C0, 55, 68, BD, 9A, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 6E, 9A, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, EC, FE, FF, FF, E8, 9F, F9, FF, FF, 8D, 55, F0, 33, C0, E8, 15, D5, FF, FF, 8B, 55, F0, B8, B8, BD, 40, 00, E8, 6C, 9D, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, B8, BD, 40, 00...
 
[+]

Entropy:
7.9850

Developed / compiled with:
Microsoft Visual C++

Code size:
35 KB (35,840 bytes)

The file lanspy_setup.exe has been discovered within the following program.

LanSpy  by LanTricks.com
Publisher's description - “LanSpy is a network security scanner, which allows getting different information about computer: Domain and NetBios names, MAC address, Server information, Domain and Domain controller information, Remote control, Time, Discs, Transports, Users, Global and local users groups, Policy settings, Shared resources, Sessions, Open files, Services, Registry and Event log information.”
lantricks.com/lanspy
12% remove it
 
Powered by Should I Remove It?

The file lanspy_setup.exe has been seen being distributed by the following 4 URLs.

Scan lanspy_setup.exe - Powered by Reason Core Security