7031055_stp.exe

iTools 应用程序

Shenzhen Thinksky Technology Co.,Ltd

Publisher:
ThinkSky  (signed by Shenzhen Thinksky Technology Co.,Ltd)

Product:
iTools 应用程序

Description:
One-stop ios device manager

Version:
1, 6, 8, 5

MD5:
9deedeb94fc5cb2203c5d907405afa89

SHA-1:
973c5cab0b70d334ba83bae95e422337d57b3df3

SHA-256:
466a1ed7b0b9fc056d1c0604c70f7c62ccd10126979ae792fcaead8d33403b8d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 7:57:31 AM UTC  (today)

File size:
6.5 MB (6,863,200 bytes)

Product version:
1, 6, 8, 5

Copyright:
Copyright (C) ThinkSky 2012 iTools

Original file name:
iTools.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\7031055_stp.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/18/2012 7:00:00 AM

Valid to:
5/19/2014 6:59:59 AM

Subject:
CN="Shenzhen Thinksky Technology Co.,Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Shenzhen Thinksky Technology Co.,Ltd", L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
436F252D3A04D8D97E1ACB45363E7F1A

File PE Metadata
Compilation timestamp:
1/10/2013 3:48:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:jfXAScX0uPDczK31AORblU7U/n2U8IdjZpr9YVajCv:jfA7XzPL8Id1UVa4

Entry address:
0x3C3F2E

Entry point:
E8, F1, 03, 00, 00, E9, 36, FD, FF, FF, FF, 25, E4, 96, 85, 00, 6A, 08, B8, 90, 6E, 81, 00, E8, 74, 04, 00, 00, FF, 75, 08, 83, 65, FC, 00, E8, 44, FC, FF, FF, 59, 89, 45, EC, 8B, 45, EC, E8, 92, 04, 00, 00, C3, 83, 65, EC, 00, B8, 5A, 3F, 7C, 00, C3, CC, FF, 25, 94, 97, 85, 00, 68, CD, 3F, 7C, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 28, A0, 91, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45...
 
[+]

Entropy:
6.7717

Code size:
4.3 MB (4,554,752 bytes)

The file 7031055_stp.exe has been seen being distributed by the following 2 URLs.

Scan 7031055_stp.exe - Powered by Reason Core Security