simsigloader.exe

Cajon Rail LLC

Publisher:
Cajon Rail LLC  (signed and verified)

Description:
SimSig Loader

Version:
4.5.8.0

MD5:
b1c37fee5f5a0e0721c87028c9466055

SHA-1:
fe6f377766e016811913afd1a0569d7148aa912b

SHA-256:
9628d6bcc6c68e63adc86967de3d07a9cd03c87856eec7b560ef296a77b066d6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 3:26:02 PM UTC  (today)

File size:
2.1 MB (2,151,920 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (C) 2012-2016 G. Mayo

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/10/2015 12:00:00 AM

Valid to:
12/9/2016 11:59:59 PM

Subject:
CN=Cajon Rail LLC, O=Cajon Rail LLC, STREET=16670 Century Plant Rd, L=Apple Valley, S=California, PostalCode=92307, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
632C1B2CE02A77F5D608DD2D2FE3C6B4

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:WJ5gF+/5HTF43UMD9UJ+lApvqrfMASG74y9gubipf+ivqEQUnc+6blTZrpGZ3xzG:W3gwDVqrv6IUnX4TZ8ZBzG

Entry address:
0x16FEA4

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 0C, F6, 56, 00, E8, 2F, 16, E9, FF, 8B, 1D, 68, DA, 57, 00, E8, 88, 11, E9, FF, A1, F4, AD, 57, 00, C6, 00, 00, 8B, 03, E8, 91, 18, E9, FF, 8B, 03, BA, 58, FF, 56, 00, E8, 75, 18, E9, FF, 8B, 0D, FC, A9, 57, 00, 8B, 03, 8B, 15, F4, FF, 49, 00, E8, 7A, 18, E9, FF, 8B, 0D, D8, AD, 57, 00, 8B, 03, 8B, 15, 94, B7, 49, 00, E8, 67, 18, E9, FF, 8B, 0D, 30, AC, 57, 00, 8B, 03, 8B, 15, C0, CE, 4B, 00, E8, 54, 18, E9, FF, 8B, 0D, 60, AD, 57, 00, 8B, 03, 8B, 15, 34, C7, 4B, 00, E8, 41...
 
[+]

Entropy:
6.5869

Developed / compiled with:
Microsoft Visual C++

Code size:
1.4 MB (1,503,232 bytes)

The file simsigloader.exe has been seen being distributed by the following URL.

Scan simsigloader.exe - Powered by Reason Core Security