sohuva_5.0.1.20-c1008-ng-x.exe

SH7zInst Application

FOX INFORMATION TECHNOLOGY (TIANJIN) LIMITED

This is a setup program which is used to install the application. The file has been seen being downloaded from p2p.hd.sohu.com.
Publisher:

Product:
SH7zInst Application

Version:
5.0.1.20

MD5:
a53fe53b458a48e2a00e83d30a5e3f94

SHA-1:
5a06c6111026197c26a2e868719405adef758184

SHA-256:
57b3deec540222f403d48ff7f1100d27013cf54ccb9cb957adfbce34e5b7e08c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 9:28:06 PM UTC  (today)

File size:
18.7 MB (19,572,856 bytes)

Product version:
5,0,1,20

Copyright:
Copyright (C) 2014

Original file name:
SH7zInst.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\sohuva_5.0.1.20-c1008-ng-x.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/30/2014 4:00:00 PM

Valid to:
12/30/2017 3:59:59 PM

Subject:
CN=FOX INFORMATION TECHNOLOGY (TIANJIN) LIMITED, OU=Product Technology Center, O=FOX INFORMATION TECHNOLOGY (TIANJIN) LIMITED, L=TIANJIN, S=TIANJIN, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
7DE0E1DC4BA0CD6A79AB70BEB93FD937

File PE Metadata
Compilation timestamp:
9/7/2015 4:32:16 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:uvmUEuVoT5T+m7lldV8pAF+7aKrBJ/YW+GmkUIEbHjrpeCj32LDZr+qBl65bopK:bjTZ+m7b/+7aaBFhn54bHjrpeu32fZ1G

Entry address:
0x83AE5

Entry point:
E8, 8E, AD, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 6A, 0A, 6A, 00, FF, 75, 08, E8, 08, B0, 00, 00, 83, C4, 0C, 5D, C3, 8B, FF, 55, 8B, EC, 5D, E9, DF, FF, FF, FF, FF, 35, B4, 32, 4E, 00, E8, DD, 6B, 00, 00, 59, 85, C0, 74, 02, FF, D0, 6A, 19, E8, 3E, A6, 00, 00, 6A, 01, 6A, 00, E8, 7C, 24, 00, 00, 83, C4, 0C, E9, 5D, 23, 00, 00, 8B, FF, 55, 8B, EC, 33, C0, 39, 45, 0C, 76, 11, 8B, 4D, 08, 66, 83, 39, 00, 74, 08, 40, 41, 41, 3B, 45, 0C, 72, F2, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 66, 8B, 55, 0C...
 
[+]

Entropy:
7.9713  (probably packed)

Code size:
680 KB (696,320 bytes)

The file sohuva_5.0.1.20-c1008-ng-x.exe has been seen being distributed by the following URL.

Scan sohuva_5.0.1.20-c1008-ng-x.exe - Powered by Reason Core Security