SrLoader.exe

Beijing Gigabit Times Technology Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SrLoader’.
Publisher:
Supper Rabbit  (signed by Beijing Gigabit Times Technology Co., Ltd)

Product:
Supper Rabbit

Version:
1.0.0.1

MD5:
a1eba437f59a2fb8f92a3086a36cb384

SHA-1:
c9c3235de728c624b7456c418d3a0e2d3fbdd7cd

SHA-256:
58cda14ab3c9e210d0f09b68a0ac20cff07abec58159add532922ab9d6bd9bd8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 10:56:52 PM UTC  (today)

File size:
263.2 KB (269,504 bytes)

Product version:
1.0.0.1

Copyright:
Supper Rabbit

Original file name:
SrLoader.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\Program Files\super rabbit\magicset\srloader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/23/2008 4:00:00 PM

Valid to:
12/24/2011 3:59:59 PM

Subject:
CN="Beijing Gigabit Times Technology Co., Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Gigabit Times Technology Co., Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
77A64759F12766E363D779998C71BDC9

File PE Metadata
Compilation timestamp:
8/7/2009 3:11:10 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1281E

Entry point:
E8, BD, 55, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 50, 0E, 43, 00, 75, 02, F3, C3, E9, 3F, 56, 00, 00, 8B, FF, 55, 8B, EC, 51, 53, 56, 57, FF, 35, C8, 5F, 43, 00, E8, 43, 50, 00, 00, FF, 35, C4, 5F, 43, 00, 8B, F8, 89, 7D, FC, E8, 33, 50, 00, 00, 8B, F0, 59, 59, 3B, F7, 0F, 82, 83, 00, 00, 00, 8B, DE, 2B, DF, 8D, 43, 04, 83, F8, 04, 72, 77, 57, E8, 72, 3F, 00, 00, 8B, F8, 8D, 43, 04, 59, 3B, F8, 73, 48, B8, 00, 08, 00, 00, 3B, F8, 73, 02, 8B, C7, 03, C7, 3B, C7, 72, 0F, 50, FF, 75, FC, E8, 70, 57, 00, 00, 59...
 
[+]

Entropy:
6.1004

Code size:
151 KB (154,624 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SrLoader

Command:
C:\Program Files\super rabbit\magicset\srloader.exe


Scan SrLoader.exe - Powered by Reason Core Security