kantoplayer.exe

Kanto Player

Globosoft S.R.L.

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.softonic.com and multiple other hosts.
Publisher:
Globosoft S.R.L.

Product:
Kanto Player

Description:
http://www.kantokaraoke.com/

Version:
9.1.0.0

MD5:
50217b236ba57bdd3c1a11da76cdb932

SHA-1:
64c22a66729d0228ead1029015ad310f1795cb3a

SHA-256:
4b6c517441f660eba5d4cab1932ec6e361d3200d5b4a391b87bb8a6e248d4d5f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 12:03:42 PM UTC  (today)

File size:
10.6 MB (11,069,590 bytes)

Product version:
9.1.0.0

Copyright:
Globosoft S.R.L. 2016

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\kantoplayer.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:4pV2v8SPP12ET0A4MX+t0riWw8V012ZJLI87wWZZ3GhGHPFrkFxYA3OODH1UW5V:YVPHGOrWwBOf7wWZB60NrkFf3OOP5V

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9977

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file kantoplayer.exe has been seen being distributed by the following 19 URLs.

http://www.softonic.com/sads/tracker.php?ev=c&co=CL&sid=fc430f1defde47cc3be569ff87ee5190&upv=338a00f78a4da0dacdee8ab4210c8510&z=download-cpd&sk=604&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F2855F489A7E48DA082B195828CE7EA758E1FA5277237AC6146B10502EEDBBF66CBB6DFFA350E744C95C42237E4D84B10151B51E8206C412669C421A7B178780023DC12ED4980F3ECD34670E16C6F27A2A73D0CB89EFB4E02AC12C271633548FC512B17EC4BDFE879B723CFDA10193F9F6300C5CE1A7F92A6BDC1F1CD1B0568FAD&h=8FD2B9938A10C8F3BCDFFEA13C6DD24484E463147649E151176B0D46ABDE7886&directdownload=1&f=69684966&d=http://www.download77.net/.../KantoPlayer.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=MX&sid=0f9fdbc7a06643c70290bcc789d3fcd5&upv=28d74fa429f658220da46928bba9b7a9&z=download-cpd&sk=614&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F2855F489A7E48DA082B195828CE7EA758E1FA5277237AC6146B10502EEDBBF66CA3244161625C1AC3CADBDB6C9F2FBD6205F2563D648189B3B7BB38CAB126780C732732C10DD762DB1C026E463A36AD5AF8B9E152D9CDD102D811DDA8CF1CD0BA90BC5AD8A02E9A7D9FCDD6891C2E3C400DE24CD660CFCC1AB53ECE9AB9B08971&h=60FD0D2A6667567F6851A26888C30DEC78189EEC019F7017ED16CEFD90E137BA&directdownload=1&f=69684966&d=http://www.download77.net/.../KantoPlayer.exe

http://en.softonic.com/sads/tracker.php?ev=c&co=BR&sid=e96222622042f0dc74a497f6b2a2d572&upv=abbb326311c3cdf3f605e160faf04d39&z=download-cpd&sk=592&abp=0&params=F39B2A32BFC101987B1458170C278E031176ABDE618A400FC6FF30446D94EAB6F5A52A746CD9DB398294587EFF600E93F0D8FEA11147246603A82B4EABAAFAED814F426120F818A014B7C35651B8F4C15915C3388A232690ECC78F56CFF4BA51A3D4A1B7143089F393601A5BA0B5A1523BCA574CF63C235E08C60CA42C8759EFF45B5C5F86C02AAE12B8852937A48126CBBF25BD947A9DF84DDC258588C86AB6&h=B11E65331E402E5F6BEF169CE31D9E355D9D82523157A136E2D55506F34EEE37&directdownload=1&f=69684966&d=http://www.download77.net/.../KantoPlayer.exe

Scan kantoplayer.exe - Powered by Reason Core Security