ManTray.exe

Tiejiaren Technology Co,LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ManTray’.
Publisher:
时刻在线  (signed by Tiejiaren Technology Co,LTD)

Product:
时刻在线

Version:
1, 0, 0, 1

MD5:
f647741e6d773570aa4a335cf996f8cf

SHA-1:
fe8dcc86fbfbb0aeb831a1de2f930aedb29d0bca

SHA-256:
237a74cc8777c20e6d39bc89f943183fe44cfdabd64c94ad24c32203923f8d85

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/19/2024 2:29:52 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win64/Riskware.oTimer
10.12413

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.9.5.0

File size:
257.9 KB (264,056 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2013 时刻在线

Original file name:
ManTray.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\roaming\ot\mantray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/15/2013 8:00:00 AM

Valid to:
11/16/2014 7:59:59 AM

Subject:
CN="Tiejiaren Technology Co,LTD", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Tiejiaren Technology Co,LTD", L=Xiamen, S=Fujian, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
55626D6273B70E9450BA60FE30AF7B5E

File PE Metadata
Compilation timestamp:
2/27/2014 3:34:11 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:UzCmQNEZalOZ88e7R2/uXRgdy3eKjaMR/p1eSeG:UzUN2acZzmX3x

Entry address:
0x15EA0

Entry point:
48, 83, EC, 28, E8, 23, 5F, 00, 00, 48, 83, C4, 28, E9, 1A, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 49, 83, F8, 08, 72, 53, 0F, B6, D2, 49, B9, 01, 01, 01, 01, 01, 01, 01, 01, 49, 0F, AF, D1, 49, 83, F8, 40, 72, 1E, 48, F7, D9, 83, E1, 07, 74, 06, 4C, 2B, C1, 48, 89, 10, 48, 03, C8, 4D, 8B, C8, 49, 83, E0, 3F, 49, C1, E9, 06, 75, 39, 4D, 8B, C8, 49, 83, E0, 07, 49, C1, E9, 03, 74, 11, 66, 66, 66, 90, 90...
 
[+]

Entropy:
6.0579

Code size:
141 KB (144,384 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ManTray

Command:
C:\users\{user}\appdata\roaming\ot\mantray.exe


Scan ManTray.exe - Powered by Reason Core Security