godrun.exe

Zhenjiang Xinqu Guangcaixingchen Information Technology Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Universal Calendar’.
Publisher:
万能日历   (signed by Zhenjiang Xinqu Guangcaixingchen Information Technology Co., Ltd)

Product:
万能日历

Description:
Calendar Run

Version:
1.1.0

MD5:
505d4c1dd1761c99b0fd612ffcf00fd1

SHA-1:
7bb3623cb5a2c2f81e5e66a485d4f304c5a7e6bf

SHA-256:
3af88212e73819f8bc2e27c50924b4aaf3abac3d995ab7c0958ae4f01b06e257

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/10/2025 7:26:53 AM UTC  (today)

File size:
506.4 KB (518,504 bytes)

Product version:
1.10

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\calendar\godrun.exe

Digital Signature
Authority:
WoSign eCommerce Services Limited

Valid from:
10/12/2013 10:47:14 AM

Valid to:
10/14/2014 5:59:22 AM

Subject:
E=masterwannen@sina.com, CN="Zhenjiang Xinqu Guangcaixingchen Information Technology Co., Ltd", O="Zhenjiang Xinqu Guangcaixingchen Information Technology Co., Ltd", L=Zhenjiang, S=Jiangsu, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign eCommerce Services Limited, C=CN

Serial number:
11FE5B39872580

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:gLdfgr6UcuR1HcE3z/LrIJCC9X6QlbC4a62hIR1K2g2pXdYxE3sD+tXji/GaaSPE:UdfaxcuRuETclDa5hIRdPdCrEji/58

Entry address:
0x56E04

Entry point:
55, 8B, EC, 83, C4, F0, B8, 54, 6C, 45, 00, E8, 30, F4, FA, FF, A1, E8, 8B, 45, 00, 8B, 00, E8, 10, 71, FF, FF, 8B, 0D, C4, 8C, 45, 00, A1, E8, 8B, 45, 00, 8B, 00, 8B, 15, 58, 65, 45, 00, E8, 10, 71, FF, FF, A1, E8, 8B, 45, 00, 8B, 00, E8, 84, 71, FF, FF, E8, 67, D4, FA, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5172

Developed / compiled with:
Microsoft Visual C++

Code size:
344 KB (352,256 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Universal Calendar

Command:
"C:\Program Files\calendar\godrun.exe" \autostart


Scan godrun.exe - Powered by Reason Core Security