megafiledownload.exe

Megafile Webhard

KTS CONTENTS CORP.

Publisher:
Megafile  (signed by KTS CONTENTS CORP.)

Product:
Megafile Webhard

Version:
1.0.0.38

MD5:
7acccf4a0d255a1a355b6ea066cbe052

SHA-1:
6b785426c3c283bcaccae648ba487cb4bcab5f0f

SHA-256:
809f843995e74e325408ecd60583c522e5dfd97ac903613ff908f4cc01c75805

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 5:00:13 PM UTC  (today)

File size:
2 MB (2,148,352 bytes)

Product version:
1.0.0.38

Copyright:
(c) Megafile. All rights reserved.

Original file name:
Download.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\megafiledownload.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/8/2010 9:00:00 AM

Valid to:
8/7/2013 8:59:59 AM

Subject:
CN=KTS CONTENTS CORP., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=KTS CONTENTS CORP., L=Bundang-gu, S=Gyeonggi-do, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
76B0246E50FCCC7B34953C50B12D115D

File PE Metadata
Compilation timestamp:
11/5/2010 6:33:51 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:w1oT9OOoCi9fTjoWqK4eU49RNZQ4CfRtvn6oJB+On3:4nYiKWqK4eU43NZDCfXvn6oJp

Entry address:
0x113096

Entry point:
E8, A5, 83, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 40, DC, 58, 00, 75, 02, F3, C3, E9, 27, 84, 00, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 20, D8, 58, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 24, D8, 58, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, 5D, 7F, 00, 00, 85, C0, 75, 06, B8, 88, D9, 58, 00, C3, 83, C0, 08, C3, E8, 4A, 7F, 00, 00, 85, C0, 75, 06, B8, 8C, D9, 58, 00, C3, 83, C0, 0C...
 
[+]

Entropy:
6.4789

Packer / compiler:
PEQuake V0.06

Code size:
1.2 MB (1,298,944 bytes)

Scan megafiledownload.exe - Powered by Reason Core Security