roguekillerx64_beta.exe

RogueKiller

Adlice

Publisher:
Adlice Software  (signed by Adlice)

Product:
RogueKiller

Description:
Anti~mal~ware tool

Version:
11.0.0.0 beta 5

MD5:
d32a52c0765e0c3fe189b933f3d314c8

SHA-1:
64187eb3aff7a8e024255103ba340075e935bd05

SHA-256:
08272689a321f2d313e66fcf857c318b5180b55fac397fe4d63a7cae1029b46e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 8:04:18 PM UTC  (today)

File size:
21.8 MB (22,817,352 bytes)

Product version:
11.0.0.0 beta 5

Copyright:
Copyright Adlice Software(C) 2015

Original file name:
RogueKiller

File type:
Executable application (Win64 EXE)

Language:
French (France)

Common path:
C:\users\{user}\downloads\roguekillerx64_beta.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/30/2015 8:00:00 PM

Valid to:
6/28/2018 8:00:00 AM

Subject:
CN=Adlice, O=Adlice, L=Orvault, S=Loire Atlantique, C=FR

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0730C248977813C25BB22568B51ED287

File PE Metadata
Compilation timestamp:
10/14/2015 4:26:13 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:qQ5jGFV3OlFHAjARIPLNyf+rW+qQxf7YUX+M8JBG9c+eJ8OII80eyJsv6tWKFduC:qhqW+W8

Entry address:
0x9797B0

Entry point:
48, 83, EC, 28, E8, 93, 53, 01, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 48, 85, C9, 74, 37, 53, 48, 83, EC, 20, 4C, 8B, C1, 48, 8B, 0D, D0, AB, 91, 00, 33, D2, FF, 15, 90, 53, 1E, 00, 85, C0, 75, 17, E8, F7, 45, 00, 00, 48, 8B, D8, FF, 15, EE, 4E, 1E, 00, 8B, C8, E8, 9F, 45, 00, 00, 89, 03, 48, 83, C4, 20, 5B, C3, CC, CC, CC, 48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 48, 8B, D9, 48, 83, F9, E0, 77, 7C, BF, 01, 00, 00, 00, 48, 85, C9, 48, 0F, 45, F9, 48, 8B, 0D, 79, AB, 91, 00, 48...
 
[+]

Entropy:
6.8393

Code size:
11.4 MB (11,915,264 bytes)

The file roguekillerx64_beta.exe has been seen being distributed by the following URL.

Scan roguekillerx64_beta.exe - Powered by Reason Core Security