DxKankan.exe

点心看电影

重庆趣玩科技有限公司

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘DIANXIN_MOVIE’.
Publisher:
重庆趣玩科技  (signed by 重庆趣玩科技有限公司)

Product:
点心看电影

Version:
1.2.4.8

MD5:
e80bbd0bbaf10d35fdec506a6060ac08

SHA-1:
d6d52ac859b76e8bdb8144a12b0b62f917e9b86d

SHA-256:
5b478ccfb4f74bff11867f07ab765d5690826a93a04c206afc28dea482da9226

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 7:36:59 AM UTC  (today)

File size:
3.8 MB (3,988,912 bytes)

Product version:
1.2.4.8

Copyright:
Copyright (C) 2014

Original file name:
DxKankan.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\dianxinmovie\dxkankan.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
4/3/2014 1:47:16 PM

Valid to:
4/4/2015 1:47:16 PM

Subject:
CN=重庆趣玩科技有限公司, E=qw20140401@163.com, O=重庆趣玩科技有限公司, L=重庆市, S=重庆市, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
60D60A150B57D970DDFC5F8BB691B6F0

File PE Metadata
Compilation timestamp:
9/30/2014 1:39:06 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:IPNIcj3Z2O2Wh2VIcGl5Uo9pECrAeFG3VDBNVogaw0I4mERSwz8P7zsWi3hwjvs0:IP75tlfyeaDBEj6ERSt7zsWi3gP

Entry address:
0x1E7CAE

Entry point:
E8, 82, 6F, 01, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, A3, CC, 2B, 74, 00, 5D, C3, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, C0, 7F, 73, 00, 33, C5, 89, 45, FC, 53, 8B, 5D, 08, 57, 83, FB, FF, 74, 07, 53, E8, E4, 6F, 01, 00, 59, 83, A5, E0, FC, FF, FF, 00, 6A, 4C, 8D, 85, E4, FC, FF, FF, 6A, 00, 50, E8, 7C, 0A, 00, 00, 8D, 85, E0, FC, FF, FF, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8...
 
[+]

Entropy:
6.6031

Code size:
2.5 MB (2,660,352 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DIANXIN_MOVIE

Command:
C:\Program Files\dianxinmovie\dxkankan.exe m=auto


Scan DxKankan.exe - Powered by Reason Core Security