ManTray.exe

Tiejiaren Technology Co,LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ManTray’.
Publisher:
时刻在线  (signed by Tiejiaren Technology Co,LTD)

Product:
时刻在线

Version:
1, 0, 0, 1

MD5:
afb58cd04500a2c5086f4d9a9ae8d596

SHA-1:
dcbea6ed33f35d65002453422d71b3e56eb0eb6e

SHA-256:
dff6b51fbacc738095edbcbecfae01dabf626aa743859417d1b3e12d95843ee0

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/24/2024 2:17:27 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win64/Riskware.oTimer.A application
6.3

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.9.5.0

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16817

File size:
257.9 KB (264,080 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2013 时刻在线

Original file name:
ManTray.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\roaming\ot\mantray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/15/2013 8:00:00 AM

Valid to:
11/16/2014 7:59:59 AM

Subject:
CN="Tiejiaren Technology Co,LTD", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Tiejiaren Technology Co,LTD", L=Xiamen, S=Fujian, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
55626D6273B70E9450BA60FE30AF7B5E

File PE Metadata
Compilation timestamp:
12/25/2013 11:06:38 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:i61bgDGLqOTpY7NgGHs9N7qtIxsV0eSeC:i6uKLbFsssm

Entry address:
0x15EA8

Entry point:
48, 83, EC, 28, E8, 1B, 5F, 00, 00, 48, 83, C4, 28, E9, 12, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 49, 83, F8, 08, 72, 53, 0F, B6, D2, 49, B9, 01, 01, 01, 01, 01, 01, 01, 01, 49, 0F, AF, D1, 49, 83, F8, 40, 72, 1E, 48, F7, D9, 83, E1, 07, 74, 06, 4C, 2B, C1, 48, 89, 10, 48, 03, C8, 4D, 8B, C8, 49, 83, E0, 3F, 49, C1, E9, 06, 75, 39, 4D, 8B, C8, 49, 83, E0, 07, 49, C1, E9, 03, 74, 11, 66, 66, 66, 90, 90, 48, 89, 11, 48, 83, C1, 08, 49...
 
[+]

Entropy:
6.0588

Code size:
141 KB (144,384 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ManTray

Command:
C:\users\{user}\appdata\roaming\ot\mantray.exe


Scan ManTray.exe - Powered by Reason Core Security