sk08l01stw==24010.exe

KROMTECH ALLIANCE CORP

Publisher:
KROMTECH ALLIANCE CORP  (signed and verified)

MD5:
d52526bf32543c5c9c241c30e224bc9e

SHA-1:
65696794d09391d555153d9e7f667bcfa0d1e347

SHA-256:
00b04f51d77892aaa521f392bb0c9249a4856f8678f6a135d00548fea8dbc87e

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/7/2024 4:54:03 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Program.Unwanted.449
9.0.1.0172

File size:
76.8 KB (78,616 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\sk08l01stw==24010.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/29/2014 8:00:00 PM

Valid to:
6/29/2015 7:59:59 PM

Subject:
CN=KROMTECH ALLIANCE CORP, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=KROMTECH ALLIANCE CORP, L=Road Town, S=Tortola, C=VG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
584891EDF831A6E0B8792E907445EDEE

File PE Metadata
Compilation timestamp:
6/16/2015 6:30:56 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
1536:lWfGFLW1uFhPfd1xZaj4c8csWjcdBLRJfO/oO:lK2W1mZD1RoN

Entry address:
0x122F

Entry point:
E8, 39, 11, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, FF, 15, 0C, C0, 40, 00, 6A, 01, A3, 04, 25, 41, 00, E8, 86, 18, 00, 00, FF, 75, 08, E8, 1B, 16, 00, 00, 83, 3D, 04, 25, 41, 00, 00, 59, 59, 75, 08, 6A, 01, E8, 6C, 18, 00, 00, 59, 68, 09, 04, 00, C0, E8, E9, 15, 00, 00, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 58, 9D, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, E8, 22, 41, 00, 89, 0D, E4, 22, 41, 00, 89, 15, E0, 22, 41, 00, 89, 1D, DC, 22, 41, 00, 89, 35, D8, 22, 41, 00, 89, 3D, D4...
 
[+]

Entropy:
6.4585

Code size:
43 KB (44,032 bytes)

The file sk08l01stw==24010.exe has been seen being distributed by the following URL.

Scan sk08l01stw==24010.exe - Powered by Reason Core Security