hm.exe

HostsMan

abelhadigital.com

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘HostsMan’.
Publisher:
abelhadigital.com

Product:
HostsMan

Version:
4.3.98.0

MD5:
76f4042606e36b566dd10d901180d192

SHA-1:
abccfc66562034fe9ec6efa605f59cead4cca2c6

SHA-256:
f2d1b73676f89bead0a1fb93ff7fe7840fe4780ab5b6b346321129cf3aea2b5d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 9:37:23 AM UTC  (today)

File size:
6.8 MB (7,120,896 bytes)

Product version:
4.3.98.0

Copyright:
Copyright © 1997-2013 abelhadigital.com

Original file name:
hm.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\hostsman\hm.exe

File PE Metadata
Compilation timestamp:
11/27/2013 12:30:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:mcNt7FhAzwH9EBU7rgSorZ3QuAquw2K8SPa/+G8qG9H1+:mctxhAzwH6BUHorpALK8SPrGxw1+

Entry address:
0x529730

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 2C, 57, 91, 00, E8, CB, 2E, AE, FF, A1, 10, F4, 94, 00, C6, 00, 01, A1, 44, FC, 94, 00, 8B, 00, E8, 23, BB, C5, FF, A1, 44, FC, 94, 00, 8B, 00, BA, 8C, 98, 92, 00, E8, 0A, B5, C5, FF, A1, 44, FC, 94, 00, 8B, 00, B2, 01, E8, 24, D8, C5, FF, E8, F3, 36, FD, FF, E8, D2, B4, FB, FF, B8, F5, A9, 9F, 00, 33, D2, E8, 7E, AF, FB, FF, 8B, D8, 84, DB, 0F, 84, BC, 00, 00, 00, F6, 05, F5, A9, 9F, 00, 02, 74, 2B, E8, 06, BE, FE, FF, 84, C0, 0F, 84, CF, 00, 00, 00, A1, AC, F8, 94, 00, 8B...
 
[+]

Entropy:
6.7477

Developed / compiled with:
Microsoft Visual C++

Code size:
5.2 MB (5,409,280 bytes)

Scheduled Task
Task name:
HostsMan

Trigger:
Logon (Runs on logon)


Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
HostsMan

Command:
"C:\Program Files\hostsman\hm.exe" -s


Scan hm.exe - Powered by Reason Core Security