WiTopia.exe

WiTopia Client

Sparklabs

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WiTopia’.
Publisher:
Sparklabs  (signed and verified)

Product:
WiTopia Client

Description:
WiTopia.exe

Version:
2.1.3.158

MD5:
1a8e43d38a6c8ec98ecd85ee94544b1c

SHA-1:
0f3c483a2a23aad5836e1e2e23de5b3cd21a16eb

SHA-256:
e6ff82b1f5036b7ac588f0cb4fadaa9939ea90a0a56d1c018296edd445322272

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 5:35:23 AM UTC  (today)

File size:
650.2 KB (665,800 bytes)

Product version:
2.1.3.0

Copyright:
(c) 2011

Original file name:
WiTopia.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\witopia\witopia.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/20/2012 9:35:37 AM

Valid to:
1/20/2014 9:35:37 AM

Subject:
E=contact@thesparklabs.com, CN=Sparklabs, O=Sparklabs, L=Bathurst, S=NSW, C=AU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11218E251B6C5528FF56B8CACD8EEB4239C8

File PE Metadata
Compilation timestamp:
9/30/2013 4:29:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:zsXvVrVhFmwWIA74scMqwQDa7YhESJT+bdddS+o:uVrVhUX0sPuW6jud3o

Entry address:
0x9A966

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.1541

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
610.5 KB (625,152 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WiTopia

Command:
C:\Program Files\witopia\witopia.exe


Scan WiTopia.exe - Powered by Reason Core Security