sim216.tmp

Cajon Rail LLC

Publisher:
Cajon Rail LLC  (signed and verified)

Description:
SimSig Loader

Version:
4.5.12.0

MD5:
5fc5323d33abe484553712fad15e4bb8

SHA-1:
916615da42a5b2cf066aa6ece94d0e5cf811fa02

SHA-256:
eadd0e4e721f0e3edeb5d10c509fbe0caf912e8af86a950228fa2402f6f9595b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/13/2025 1:48:58 AM UTC  (today)

File size:
2 MB (2,148,504 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (C) 2012-2016 G. Mayo

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\temp\sim216.tmp

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/10/2015 12:00:00 AM

Valid to:
12/9/2016 11:59:59 PM

Subject:
CN=Cajon Rail LLC, O=Cajon Rail LLC, STREET=16670 Century Plant Rd, L=Apple Valley, S=California, PostalCode=92307, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
632C1B2CE02A77F5D608DD2D2FE3C6B4

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:gZOzmp8OrIerJiOt6v/8x2UnAR1OVaeIu24Tj4dmvp+ZQ/WKQu+6JVTZCc3xYyfv:zSpljOSaO1/WKsOTZHBYo

Entry address:
0x17005C

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, DC, F7, 56, 00, E8, AF, 14, E9, FF, 8B, 1D, 40, F5, 57, 00, E8, D0, 0F, E9, FF, A1, 00, BE, 57, 00, C6, 00, 00, 8B, 03, E8, 0D, 2C, E9, FF, 8B, 03, BA, 24, 01, 57, 00, E8, F1, 2B, E9, FF, 8B, 0D, 10, BA, 57, 00, 8B, 03, 8B, 15, 50, 2C, 4A, 00, E8, F6, 2B, E9, FF, 8B, 0D, E4, BD, 57, 00, 8B, 03, 8B, 15, 80, E5, 49, 00, E8, E3, 2B, E9, FF, 8B, 0D, 48, BC, 57, 00, 8B, 03, 8B, 15, 04, 01, 4C, 00, E8, D0, 2B, E9, FF, 8B, 0D, 74, BD, 57, 00, 8B, 03, 8B, 15, 78, F9, 4B, 00, E8, BD...
 
[+]

Entropy:
6.5851

Developed / compiled with:
Microsoft Visual C++

Code size:
1.4 MB (1,503,744 bytes)

The file sim216.tmp has been seen being distributed by the following URL.

http://www.simsig.co.uk/SimSigUpdate/.../SimSigLoader4_5_12.exe

Scan sim216.tmp - Powered by Reason Core Security