xajh.exe

Beijing Perfect World Network Technology Co.,Ltd.

Publisher:

MD5:
8fbeccec5ada51f00cf4bf0d25b86acd

SHA-1:
394bb53767d5ae4867c1efa4cbaad3f9ba389304

SHA-256:
7f2fec199a6e23f2912a1405a0fdf94022f09bec2b7c217afb1c4135d38a9172

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 7:30:39 PM UTC  (today)

File size:
15.8 MB (16,601,944 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\swordsman forvard 0.3.10 releas\bin\xajh.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/6/2012 3:00:00 AM

Valid to:
5/6/2015 2:59:59 AM

Subject:
CN="Beijing Perfect World Network Technology Co.,Ltd.", OU=System Center, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Perfect World Network Technology Co.,Ltd.", L=Binjing, S=Binjing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
201A0B1D4F32E7AD172D9D9181FAAD6A

File PE Metadata
Compilation timestamp:
2/11/2014 5:00:19 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
393216:2OlZlPZnv1INj4XemoAXfu/ZVYDGp5aChJ4RkQVjZ7rDnWoVuC:2OlZlPJ1Ip4XemlXfu/ZBgkQVt/DnWyP

Entry address:
0xBFCCAF

Entry point:
E8, 10, 0C, 00, 00, E9, 36, FD, FF, FF, CC, FF, 25, 24, 47, 11, 01, FF, 25, 20, 47, 11, 01, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 14, 47, 11, 01, 53, 8A, 5C, 24, 08, F6, C3, 02, 56, 8B, F1, 74, 24, 57, 68, 8E, DB, FF, 00, 8D, 7E, FC, FF, 37, 6A, 0C, 56, E8, A0, 00, 00, 00, F6, C3, 01, 74, 07, 57, E8, BF, FF, FF, FF, 59, 8B, C7, 5F, EB, 13, E8, 82, 0E, 00, 00, F6, C3, 01, 74, 07, 56, E8, A9, FF, FF, FF, 59, 8B, C6, 5E, 5B, C2, 04, 00, CC, FF, 25, 10, 47, 11, 01, FF, 25, 0C, 47, 11, 01, FF, 25, 08...
 
[+]

Code size:
13.1 MB (13,709,312 bytes)

Scan xajh.exe - Powered by Reason Core Security