PAS.exe

PAS

Softnyx Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PasLocation’.
Publisher:
Softnyx  (signed by Softnyx Co., Ltd.)

Product:
PAS

Version:
1.0.0.1

MD5:
a7d5a63a42e9e9ce59009e374bf5c3cb

SHA-1:
f592792cc235388edd9d679b44f2845a387b5a7c

SHA-256:
aa3c140c1c982935814924bc198b8f4114f4cb0b091d7c57809544b8a854562b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 7:54:08 AM UTC  (today)

File size:
928.6 KB (950,856 bytes)

Product version:
1.0.0.1

Copyright:
Softnyx. All rights reserved.

Original file name:
PAS.exe

File type:
Executable application (Win32 EXE)

Language:
Korean

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/11/2012 9:00:00 PM

Valid to:
4/12/2013 8:59:59 PM

Subject:
CN="Softnyx Co., Ltd.", OU=Server Development Team, O="Softnyx Co., Ltd.", L=Geumcheon-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
67EC9D5141EC2A9D9D3D6EDB2F301C9B

File PE Metadata
Compilation timestamp:
1/21/2013 4:48:37 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:Bu0SSQfpyBSyQf7aDVk6txOFZb5ZeNOm1Co+6KTrOYUj+:RZQNfSi6txOXySL/TCYUj

Entry address:
0x83F9C

Entry point:
E8, CE, BA, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 14, 53, FF, 75, 10, 33, DB, 8D, 4D, EC, 89, 5D, FC, E8, 0E, F4, FF, FF, 8B, 4D, 08, 3B, CB, 75, 28, E8, 33, 37, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, EC, D8, FF, FF, 83, C4, 14, 38, 5D, F8, 74, 07, 8B, 45, F4, 83, 60, 70, FD, 33, C0, EB, 71, 56, 8B, 75, F0, 39, 5E, 08, 75, 19, FF, 75, 0C, 51, E8, 60, 0B, 00, 00, 59, 59, 38, 5D, F8, 74, 57, 8B, 4D, F4, 83, 61, 70, FD, EB, 4E, 57, 8A, 11, 0F, B6, C2, 0F, B6, F8, F6, 44, 37...
 
[+]

Code size:
719.5 KB (736,768 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PasLocation

Command:
C:\pas\pas.exe


Scan PAS.exe - Powered by Reason Core Security