darklightsetup-yeqido.exe

Fancy3D Launcher

Beijing FancyGuo Tech Ltd

This is a setup program which is used to install the application. The file has been seen being downloaded from admin-darklight.gameforest.in.th and multiple other hosts.
Publisher:
Hongfeng Hengyu (Beijing) Tech Ltd.  (signed by Beijing FancyGuo Tech Ltd)

Product:
Fancy3D Launcher

Version:
0,15,0313,1113

MD5:
cb96d1a4045fadc70e6cff08597a037a

SHA-1:
e3ed9d7ffcb618105850184ccf68373cdb693511

SHA-256:
e8d3e1d593eb06ebfb5c497dab0bb43426268b213f9bb787c0b20508ab489895

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 6:42:08 PM UTC  (today)

File size:
2.2 MB (2,275,128 bytes)

Product version:
0,15,0313,1113

Copyright:
Copyright (C) Hongfeng Hengyu 2009 - 2015. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\darklightsetup-yeqido.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/6/2013 7:00:00 AM

Valid to:
6/6/2015 6:59:59 AM

Subject:
CN=Beijing FancyGuo Tech Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Beijing FancyGuo Tech Ltd, L=BeiJing, S=BeiJing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4063E34CC2E877E0152EB5CB6DA6FD79

File PE Metadata
Compilation timestamp:
3/13/2015 10:13:19 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:o3EsKEuMEwlHYf+8AbMr4kvh2774n6CCW8XdBp/N:8Lut+YTAQrk786fNXdTN

Entry address:
0x2E8730

Entry point:
60, BE, 00, 20, 4D, 00, 8D, BE, 00, F0, F2, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 28, 65, 2E, 00, 57, 83, C3, 04, 53, 68, 21, 67, 21, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.9839  (probably packed)

Code size:
2.1 MB (2,195,456 bytes)

The file darklightsetup-yeqido.exe has been seen being distributed by the following 31 URLs.

http://.../dl?t=dl&s=http://.../6.html?gw=1&time=1447394106&uid=400019999&sid=6&uf=0&op=gameforest&sign=a5bc029e6a4db56409a692d3c757c106

http://.../dl?t=dl&s=http://.../20.html?gw=1&time=1441095524&uid=260022737&sid=20&uf=100001&op=gameforest&sign=ac4aff561a5b94283a2e4a3ab27af967

http://.../dl?t=dl&s=http://.../11.html?gw=1&time=1434637298&uid=400019371&sid=11&uf=100002&op=gameforest&sign=0738aa6b7e5f5016422d93d2f122b8b5

http://.../dl?t=dl&s=http://.../7.html?gw=1&time=1432547123&uid=140019766&sid=7&uf=100002&op=gameforest&sign=5fde3736531d9ae4886be9aaec962816

http://.../dl?t=dl&s=http://.../20.html?gw=1&time=1440808199&uid=260004975&sid=20&uf=70011&op=gameforest&sign=cde84ffc2663e3f564c7e06547545a9e

http://.../dl?t=dl&s=http://.../8.html?gw=1&time=1433226908&uid=220020259&sid=8&uf=100001&op=gameforest&sign=bdf770079f3348a11976704c442bc1c9

Latest 30 of 31 download URLs

Scan darklightsetup-yeqido.exe - Powered by Reason Core Security