netkeeper.exe

闪讯1.1

Xi'an Xinli Software Technology Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Netkeeper1.0’.
Publisher:
XI AN XINLI SOFTWARE TECHNOLOGY CO.,LTD  (signed by Xi'an Xinli Software Technology Co.,Ltd.)

Product:
闪讯1.1

Description:
DialTerminal Microsoft 基础类应用程序

Version:
0, 1, 8, 0

MD5:
aa7fb018a04e4591687552f3a9f3fbf9

SHA-1:
ebb1b197739dc206cc191b373e643222c7ac3c50

SHA-256:
58cbb5a800bcbfc7030870f5696f13ff29b51a2b55b1d3b029a86718070299d4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 5:43:54 AM UTC  (today)

File size:
9 MB (9,440,920 bytes)

Product version:
1, 1, 8, 0

Copyright:
版权所有 (C) 2008 - 2013

Original file name:
DialTerminal.EXE

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/5/2013 8:00:00 AM

Valid to:
3/18/2014 7:59:59 AM

Subject:
CN="Xi'an Xinli Software Technology Co.,Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Xi'an Xinli Software Technology Co.,Ltd.", L=Xi'an, S=Shaanxi, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6A2E339A4DDE0EA8DAA823A4BA7E3297

File PE Metadata
Compilation timestamp:
9/23/2013 9:59:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:0byGrtEHk29U8TIjp5DSO7akF/az73wICHaO09mRnJ21TqF0YqQsSj:0bTiVkpZ0kFkRCHd09Swq+FQsSj

Entry address:
0x9EA05F

Entry point:
9C, C7, 04, 24, 35, 8C, B9, E8, 68, 68, 33, C3, DB, 9C, C7, 44, 24, 04, B8, F5, E6, B0, 66, 89, 2C, 24, 9C, FF, 34, 24, C6, 44, 24, 08, 71, 8D, 64, 24, 0C, E9, 1B, 9D, 83, 00, 89, 04, 24, 60, 60, 9C, FF, 74, 24, 44, C2, 48, 00, A0, 86, 18, 38, 0B, 02, D8, C5, EE, 9D, E1, B6, 3E, 50, 46, 47, 80, 65, 88, 20, 1A, 9D, F3, 37, F0, 4A, B1, 04, 1E, 2A, B6, 44, 22, 2E, 20, 3C, C4, 64, F8, B3, 2F, 97, 1B, DD, 5E, 3B, D0, 06, 84, 39, EA, 31, 6B, E5, 05, 9D, 2A, 22, EA, 0E, 56, 14, 4E, 07, 3B, 32, D9, 95, 18, C2, 70...
 
[+]

Entropy:
7.8500  (probably packed)

Code size:
1.3 MB (1,363,968 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Netkeeper1.0

Command:
C:\chinanetsn\bin\netkeeper.exe


Scan netkeeper.exe - Powered by Reason Core Security