jysgdownloader.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from dl.9yangpc.woniu.com.
MD5:
4f48b376fd6c6644ae66e133bdd5cb39

SHA-1:
c0d4c50556b23051610b6656e7df76731e2df611

SHA-256:
a04f8b3aed4a3a92aea2881da5f71d01702155024d06cc8cb614501888f2666a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/17/2024 7:22:09 PM UTC  (today)

File size:
750.6 KB (768,664 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\jysgdownloader.exe

File PE Metadata
Compilation timestamp:
4/20/2016 10:55:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:YlF3CEMIQsaiAdAfdhmUUtuuimbvGx3FJKHrbfovaiPJpOmios5iUNDn4ZF:kwaKFUouuL0vKXfovXBw35iUNDn4b

Entry address:
0x340D9

Entry point:
E8, 45, 7A, 00, 00, E9, 17, FE, FF, FF, 6A, 0C, 68, 30, 3A, 46, 00, E8, D5, 56, 00, 00, 33, C0, 33, F6, 39, 75, 08, 0F, 95, C0, 3B, C6, 75, 1D, E8, 9B, 55, 00, 00, C7, 00, 16, 00, 00, 00, 56, 56, 56, 56, 56, E8, 01, 41, 00, 00, 83, C4, 14, 83, C8, FF, EB, 5F, E8, 2C, 7B, 00, 00, 6A, 20, 5B, 03, C3, 50, 6A, 01, E8, 32, 7C, 00, 00, 59, 59, 89, 75, FC, E8, 15, 7B, 00, 00, 03, C3, 50, E8, AE, 7C, 00, 00, 59, 8B, F8, 8D, 45, 0C, 50, 56, FF, 75, 08, E8, FD, 7A, 00, 00, 03, C3, 50, E8, AA, 7D, 00, 00, 89, 45, E4...
 
[+]

Code size:
332 KB (339,968 bytes)

The file jysgdownloader.exe has been seen being distributed by the following URL.

Scan jysgdownloader.exe - Powered by Reason Core Security