FastaPingRebirth.exe

FastaPing Rebirth

Dongwoo Shin

Publisher:
byCPP  (signed by Dongwoo Shin)

Product:
FastaPing Rebirth

Version:
0.0.0.0

MD5:
40c9e40800363d55b7ce404b68c31d7b

SHA-1:
3c3e529767471c2c15366e7176ec0e196dd1d94e

SHA-256:
0c95e332014843da2e5047df24f6a5bc83be37cc06a205744b0b23131a82cd22

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 5:38:32 AM UTC  (today)

File size:
221.7 KB (227,064 bytes)

Product version:
0.0.0.0

Copyright:
Dongwoo Shin(http://www.byCPP.com)

Original file name:
FastaPingRebirth.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
5/10/2015 12:41:38 AM

Valid to:
5/10/2017 5:52:05 AM

Subject:
E=shadow26@hanmail.net, CN=Dongwoo Shin, L=Daegu, S=Taegu-jikhalsi, C=KR

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
11850E4B32C032

File PE Metadata
Compilation timestamp:
5/26/2015 11:03:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:ERPMI6K4gedqDW53d6yg4GlLafZI9mKYE3PQo4AvPj3+:EGpLADW53d63RXJTT3+

Entry address:
0x16A44

Entry point:
E8, CA, 54, 00, 00, E9, 7F, FE, FF, FF, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, E8, 28, 43, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA, 25, 88, 01, 43, 00, 01, 0F, 82, 07, 56, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74...
 
[+]

Entropy:
6.3486

Code size:
141 KB (144,384 bytes)

The file FastaPingRebirth.exe has been seen being distributed by the following 3 URLs.

http://low.software.dn.naver.com/f4b6ad4977ab8009690176bd4ebbf8c8/.../FastaPingRebirth.exe

http://www.bycpp.net/.../cfile30.uf@2518EC4C5564259307E3C2.exe

Scan FastaPingRebirth.exe - Powered by Reason Core Security