twinst_6.2.0.128.exe

TheWorld

北京世界星辉科技有限责任公司

This is a setup program which is used to install the application. The file has been seen being downloaded from yz.app.sogou.com and multiple other hosts.
Publisher:
TheWorld.CN  (signed by 北京世界星辉科技有限责任公司)

Product:
TheWorld

Version:
6.2.0.128

MD5:
10324250041be3a86bc044d542fc8b3f

SHA-1:
b68063d99ad7a560127dce8158470445a1abb70a

SHA-256:
8a7650f30d40495a4b42bbe1c3e21ddab8aa7ea7f2cb08ba888588d44bd73e81

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 6:22:55 PM UTC  (today)

File size:
16.5 MB (17,308,712 bytes)

Product version:
6.2.0.128

Copyright:
Copyright@2004-2014 The TheWorld.CN Authors. All rights reserved.

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\twinst_6.2.0.128.exe

Digital Signature
Authority:
WoSign eCommerce Services Limited

Valid from:
7/1/2013 6:20:05 PM

Valid to:
10/4/2016 5:41:28 PM

Subject:
E=support@theworld.cn, CN=北京世界星辉科技有限责任公司, O=北京世界星辉科技有限责任公司, L=北京市, S=北京市, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign eCommerce Services Limited, C=CN

Serial number:
12511C863BFA13

File PE Metadata
Compilation timestamp:
4/17/2014 5:47:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:4YPfKj7eqkwhy4AqUDYuG7V6AknChrZKK9/Yqb:HnKj7e60S6AlzftYqb

Entry address:
0x2990

Entry point:
6A, 00, FF, 15, A4, 10, 40, 00, 50, E8, D2, FE, FF, FF, 59, 50, FF, 15, A0, 10, 40, 00, CC, 8B, 01, 85, C0, 74, 09, 83, 79, 0C, 01, 7C, 03, 8B, 00, C3, 33, C0, C3, 53, 56, 8B, F1, 8B, 06, 33, DB, 3B, C3, 74, 09, 50, FF, 15, A8, 10, 40, 00, 89, 1E, 89, 5E, 08, 89, 5E, 10, 89, 5E, 0C, 89, 5E, 14, 88, 5E, 18, C7, 46, 04, 20, 11, 40, 00, 5E, 5B, C3, 55, 8B, EC, 56, 57, 8B, F1, E8, C6, FF, FF, FF, 8B, 45, 08, 8D, 7E, 0C, 57, 50, 89, 46, 08, FF, 15, C8, 10, 40, 00, 89, 06, 85, C0, 0F, 84, F5, 00, 00, 00, 33, C0...
 
[+]

Entropy:
7.9990

Packer / compiler:
FASM v1.3x

Code size:
9 KB (9,216 bytes)

The file twinst_6.2.0.128.exe has been seen being distributed by the following 4 URLs.

http://yz.app.sogou.com/download?url=http://xiazai.sogou.com/comm/redir?softdown=1&u=YRyEVuHeM45mBjjEUSPVUEJm8GF_McJfVdEjKPrgnocp6RPTnPFSKls2-N19zn1V3OIhgnxm_AlsipUd8ZPGCKrHmAlohI-Z5xWab8-hdzEZwANlQSdM_SG1O7Kkpbde98B6SY4clrbMXmmkh16MZMnFugp9LyMZfOhn_P707MFO97Z8BzEWoJ7_q9u1Veejl1h5118x5RY.&pcid=-7995648301148890109&filename=TWInst_6.2.0.128.exe&surl=&iconurl=http://dl.app.sogou.com/.../-7995648301148890109.png&name=???????&softsize=16.51MB&browser=chrome

Scan twinst_6.2.0.128.exe - Powered by Reason Core Security