DxKankan.exe

点心看电影

重庆趣玩科技有限公司

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘DIANXIN_MOVIE’.
Publisher:
重庆趣玩科技  (signed by 重庆趣玩科技有限公司)

Product:
点心看电影

Version:
1.2.4.2

MD5:
3f1b536ccc36b43ccea4ad24e56630dd

SHA-1:
b092fe1225fd575848e50bf09ef03de0f37066c0

SHA-256:
494d0b2d786c82e72e52cfd842bc393a2d7d476bf43e97e555fd373a128d8a6e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 7:49:13 AM UTC  (today)

File size:
2.6 MB (2,754,312 bytes)

Product version:
1.2.4.2

Copyright:
Copyright (C) 2014

Original file name:
DxKankan.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\dianxinmovie\dxkankan.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
4/3/2014 1:47:16 PM

Valid to:
4/4/2015 1:47:16 PM

Subject:
CN=重庆趣玩科技有限公司, E=qw20140401@163.com, O=重庆趣玩科技有限公司, L=重庆市, S=重庆市, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
60D60A150B57D970DDFC5F8BB691B6F0

File PE Metadata
Compilation timestamp:
7/24/2014 4:47:16 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:oQxElWBrl6CpVN4WQCNyUaUyXQssonPpL7TqmMXcndd+K5VmY7hk4nb4iWw/L1Kg:oQxEl4BpnQFUaUyXQ8nPpnTXMXcnddvV

Entry address:
0x166146

Entry point:
E8, AA, F4, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, A3, A8, 9C, 61, 00, 5D, C3, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, F0, FE, 60, 00, 33, C5, 89, 45, FC, 53, 8B, 5D, 08, 57, 83, FB, FF, 74, 07, 53, E8, 0C, F5, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 6A, 4C, 8D, 85, E4, FC, FF, FF, 6A, 00, 50, E8, 14, 08, 00, 00, 8D, 85, E0, FC, FF, FF, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8...
 
[+]

Entropy:
6.4868

Code size:
1.6 MB (1,664,000 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DIANXIN_MOVIE

Command:
C:\Program Files\dianxinmovie\dxkankan.exe m=auto


Scan DxKankan.exe - Powered by Reason Core Security