fstool.exe

Finger Power Technology Co., Ltd.

This is a setup program which is used to install the application. The file has been seen being downloaded from download.kingoapp.com.
Publisher:
Finger Power Technology Co., Ltd.  (signed and verified)

MD5:
08538346e1d5ff172644c68fbd11d05a

SHA-1:
4c0eb4d0350768bfd0a2821ceb2dec082354d737

SHA-256:
0187b598e02b9366570980bedeb176fd56596d2bd7c5c704d7a68ad1a66c9dae

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/13/2025 12:50:48 AM UTC  (today)

File size:
398.7 KB (408,224 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kingo root\tools\fstool.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
5/12/2016 3:00:00 AM

Valid to:
6/9/2016 2:59:59 AM

Subject:
CN="Finger Power Technology Co., Ltd.", OU=Development, O="Finger Power Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
515817CA17803F8323889FF73ECF5385

File PE Metadata
Compilation timestamp:
3/7/2014 3:52:27 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.23

CTPH (ssdeep):
6144:pbEj62X3Ab5kzIx5Jrlprkx/zfaomIKcruIQB726SBKae55+i5MQpx0PzI:pDW3AmzIxbBpWLi0KcDS726ZX+iWvzI

Entry address:
0xBB631

Entry point:
0F, 82, DB, 82, FC, FF, 68, C3, 32, 9E, 6B, E8, 67, 4D, FD, FF, 96, AB, BC, D4, CC, 7B, DD, 71, 64, C9, 0B, AE, 72, 3B, E5, E4, 82, DB, E5, 78, BC, DD, DF, 5E, 9A, 17, D9, E0, 3C, 95, 01, 70, B4, E5, ED, DD, 09, D3, 49, BA, 1F, 16, C0, 4F, 7A, 39, 33, 21, 19, 02, 24, 62, 47, FD, 90, EA, EB, 28, 55, E8, 93, 5C, 34, CD, 22, FB, 72, CF, FD, BF, E6, FD, DB, 6E, 97, 77, 5E, E3, CC, 2B, 1A, DE, C3, 9B, 3E, 8A, 1B, 49, 70, 52, 93, EB, CA, A4, D1, C9, 94, E0, C9, C1, 40, F8, BD, F3, 86, BE, E3, 8C, 64, 63, 32, F9...
 
[+]

Entropy:
7.6404

Code size:
96.5 KB (98,816 bytes)

The file fstool.exe has been seen being distributed by the following URL.

Scan fstool.exe - Powered by Reason Core Security