fqvvaaaa.exe

K-Defense Manager

Kings Information & Network Co., Ltd.

Publisher:
Kings Information & Network Co., Ltd  (signed by Kings Information & Network Co., Ltd.)

Product:
K-Defense Manager

Description:
k-Defense R6 Manager

Version:
6.1.6.4

MD5:
f5965b95cbb31c2307ce923b5b6e49c6

SHA-1:
10362af5a2d97d619c82a792b8ad6c2ec4344961

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 10:25:26 PM UTC  (today)

File size:
2.3 MB (2,397,448 bytes)

Product version:
K-Defense R6

Copyright:
Copyright 2016 Kings Information & Network Co., Ltd

Original file name:
kdfmgr.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\fqvvaaaa.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/19/2016 9:00:00 AM

Valid to:
4/20/2017 8:59:59 AM

Subject:
CN="Kings Information & Network Co., Ltd.", O="Kings Information & Network Co., Ltd.", L=Hanam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
37B11C5976BE695427C97655FD46B9D5

File PE Metadata
Compilation timestamp:
4/26/2016 5:53:42 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:riY1SnbqeaGAirAgP2i+vHG18bqeeuL2JmfY+mPNIn0C9fHhk3rMKrz+wkFpv8:rvEAirA62i+/GJFC9/h4rhuFR8

Entry address:
0x14065

Entry point:
E8, 13, B7, 00, 00, E9, 89, FE, FF, FF, 6A, 0C, 68, D0, 67, 43, 00, E8, 55, 5B, 00, 00, 6A, 0E, E8, B1, AA, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, F8, D0, 43, 00, BA, F4, D0, 43, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 10, FD, FF, FF, 59, FF, 76, 04, E8, 07, FD, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 44, 5B, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, 65, A9, 00, 00, 59, C3, 6A, 0C, 68, F0, 67, 43...
 
[+]

Entropy:
6.3113

Code size:
191 KB (195,584 bytes)

Scan fqvvaaaa.exe - Powered by Reason Core Security