hyperclassagent.exe

Igloo systems Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘HyperClass Agent’.
Publisher:
Igloo systems Inc.  (signed and verified)

MD5:
6f1f6375362687a8dda1b6710d312326

SHA-1:
30c02334ae0d1cee6a4412dbd86002bd542d7d47

SHA-256:
8289b7b2e66adb53e12370717ed0bcea8aea6bff0aa02ed12529397d0b1a7fba

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 1:27:09 AM UTC  (today)

File size:
3.4 MB (3,574,720 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\syswow64\hyperclassagent.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/13/2016 9:00:00 AM

Valid to:
1/5/2017 8:59:59 AM

Subject:
CN=Igloo systems Inc., O=Igloo systems Inc., L=Namyangju-si, S=Gyeonggi-do, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6E0AB58D99158D508E3DC581FEF196DD

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x206BB0

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 58, 64, 60, 00, E8, 23, 04, E0, FF, 8B, 1D, 3C, 49, 61, 00, 33, C0, 55, 68, BC, 6C, 60, 00, 64, FF, 30, 64, 89, 20, 6A, EC, 8B, 03, 8B, 40, 30, 50, E8, 62, 12, E0, FF, 0D, 80, 00, 00, 00, 50, 6A, EC, 8B, 03, 8B, 40, 30, 50, E8, B7, 14, E0, FF, 8B, 03, E8, C8, 51, E8, FF, 8B, 0D, D4, 41, 61, 00, 8B, 03, 8B, 15, 74, 26, 5C, 00, E8, CD, 51, E8, FF, 8B, 0D, FC, 49, 61, 00, 8B, 03, 8B, 15, A8, 21, 59, 00, E8, BA, 51, E8, FF, 8B, 0D, 44, 4E, 61, 00, 8B, 03, 8B, 15, 0C, 0B, 59, 00...
 
[+]

Entropy:
6.6702

Developed / compiled with:
Microsoft Visual C++

Code size:
2 MB (2,121,216 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
HyperClass Agent

Command:
"C:\windows\syswow64\hyperclassagent.exe"


Scan hyperclassagent.exe - Powered by Reason Core Security