HanZip.exe

HanZip

DreamWiz Internet Co.,Ltd

The executable HanZip.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
DreamWiz Internet  (signed by DreamWiz Internet Co.,Ltd)

Product:
HanZip

Version:
2.0.0.54

MD5:
d73ac57128f377e665309adeb4ea56e0

SHA-1:
c1e2a348c6ce9fe9deffd3ddedb7f2a8a36481f7

SHA-256:
0a8195ee4f51d10da897aa0b61fd3d0164e477bb7a42a9e3d2919462d9104096

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/15/2024 11:33:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.12.21.3

File size:
6.9 MB (7,274,248 bytes)

Product version:
2.0.0.0

Copyright:
Copyright(C) 2012 by DreamWiz Internet all right reserved

Original file name:
HanZip.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\hantools\hanzip\hanzip.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
12/4/2015 9:00:00 AM

Valid to:
1/3/2017 8:59:59 AM

Subject:
CN="DreamWiz Internet Co.,Ltd", OU=IT Team, O="DreamWiz Internet Co.,Ltd", L=Guro-gu, S=SEOUL, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2C28441B5E4D45C0B4A25EBFE0B40940

File PE Metadata
Compilation timestamp:
1/14/2016 4:22:28 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x531050

Entry point:
55, 53, 48, 83, EC, 68, 48, 8B, EC, 48, C7, 45, 20, 00, 00, 00, 00, 48, C7, 45, 30, 00, 00, 00, 00, 48, C7, 45, 28, 00, 00, 00, 00, 48, C7, 45, 40, 00, 00, 00, 00, 48, C7, 45, 38, 00, 00, 00, 00, 48, 89, 6D, 48, 90, 48, 8D, 0D, 8B, 85, FE, FF, E8, 5E, 31, AE, FF, 90, 48, 8B, 05, B6, 5E, 07, 00, 48, 8B, 08, E8, 1E, F9, CE, FF, 48, 8B, 05, A7, 5E, 07, 00, 48, 8B, 08, 48, 8D, 15, C9, 02, 00, 00, E8, 08, F1, CE, FF, 48, 8B, 0D, 49, 5E, B3, FF, B2, 01, E8, 0A, AE, B4, FF, 48, 89, 05, 53, 92, 29, 00, 90, 48, 8D...
 
[+]

Entropy:
5.9568

Code size:
5.2 MB (5,441,024 bytes)

Remove HanZip.exe - Powered by Reason Core Security