Ancient Ancestry.exe

Ancient Ancestry

Felix CHANDRAKUMAR

This is a setup program which is used to install the application. The file has been seen being downloaded from drive.google.com.
Publisher:
Genetic Genealogy Tools  (signed by Felix CHANDRAKUMAR)

Product:
Ancient Ancestry

Version:
1.0

MD5:
f63d04073f072f0746664c2ace8d631d

SHA-1:
2ddd3b66aaaec822ceba64756cdcf396a58eec33

SHA-256:
f1b7f266ad66feb28e909f401254c200916222239bdfc2d7982f79990f2eec30

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 12:18:49 AM UTC  (today)

File size:
4.9 MB (5,137,424 bytes)

Product version:
1.0

Copyright:
Copyright © Felix Chandrakumar 2014

Original file name:
Ancient Ancestry.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ancient ancestry.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
8/26/2014 11:48:45 PM

Valid to:
8/26/2015 11:48:45 PM

Subject:
E=i@fc.id.au, CN="Open Source Developer, Felix CHANDRAKUMAR", O=Felix CHANDRAKUMAR, C=AU

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
24CFAA920DFC035197485C2B5BA6B30D

File PE Metadata
Compilation timestamp:
11/19/2014 4:28:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:jlGSquTy4Llr1Sn9vVM8zMKgsCPvoZ4DSmGvldwG:O3X4PY4GX

Entry address:
0x4CAFEE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 70, 00, 00, 80, 10, 00, 00, 00, 88, 00, 00, 80, 18, 00, 00, 00, A0, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 06, 00, 02, 00, 00, 00, B8, 00, 00, 80, 03, 00, 00, 00, D0, 00, 00, 80, 04, 00, 00, 00, E8, 00, 00, 80, 05, 00, 00, 00, 00, 01, 00, 80, 06, 00, 00, 00, 18, 01, 00, 80, 07, 00, 00, 00, 30, 01...
 
[+]

Entropy:
7.8732

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
4.8 MB (5,017,600 bytes)

The file Ancient Ancestry.exe has been seen being distributed by the following URL.

Scan Ancient Ancestry.exe - Powered by Reason Core Security