wuzun-zm-158383-v3.exe

唐门武尊

Beijing Chuangtong Huasheng Technology Co., LTD

Publisher:
TONNN Inc.  (signed by Beijing Chuangtong Huasheng Technology Co., LTD)

Product:
唐门武尊

Description:
唐门武尊安装程序

Version:
1, 0, 1, 2

MD5:
99de08973abdc9f95f31498517bc201c

SHA-1:
05c8ec1e0182404a5c1142741803ee2f9e033d4c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 1:51:19 PM UTC  (today)

File size:
239.1 KB (244,832 bytes)

Product version:
1, 0, 1, 2

Copyright:
Copyright 2010-2014 TONNN Inc. All Rights Reserved.

Original file name:
WZInstall.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\audioplayer\wuzun-zm-158383-v3.exe

Digital Signature
Authority:
WoSign eCommerce Services Limited

Valid from:
9/5/2012 9:53:22 PM

Valid to:
9/10/2015 9:44:53 AM

Subject:
E=info@jx6.com, CN="Beijing Chuangtong Huasheng Technology Co., LTD", O="Beijing Chuangtong Huasheng Technology Co., LTD", L=Beijing, S=Beijing, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign eCommerce Services Limited, C=CN

Serial number:
16889BFB99D0AF

File PE Metadata
Compilation timestamp:
2/25/2014 5:06:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:FTHgMR+kVWNvlUKq1G0gfJBFBxLkLHEXm2Kg97TEPdcjdXQ9g6ZwOyTObKb:dHNR+kVCjfkLHE2i7TEIdIg6zyToq

Entry address:
0xDF6F

Entry point:
55, 8B, EC, 6A, FF, 68, A8, F3, 40, 00, 68, EA, E1, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 5C, F1, 40, 00, 59, 83, 0D, C4, 4F, 41, 00, FF, 83, 0D, C8, 4F, 41, 00, FF, FF, 15, 60, F1, 40, 00, 8B, 0D, A4, 2F, 41, 00, 89, 08, FF, 15, 64, F1, 40, 00, 8B, 0D, A0, 2F, 41, 00, 89, 08, A1, 68, F1, 40, 00, 8B, 00, A3, C0, 4F, 41, 00, E8, 0B, 02, 00, 00, 39, 1D, 30, 28, 41, 00, 75, 0C, 68, E6, E1, 40, 00, FF, 15, 6C, F1...
 
[+]

Entropy:
7.2097

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
56 KB (57,344 bytes)

Scan wuzun-zm-158383-v3.exe - Powered by Reason Core Security