KBrowser.exe

超快浏览器

Liu Hang

Publisher:
Liu Hang  (signed and verified)

Product:
超快浏览器

Version:
3.3.1.6

MD5:
8150ce5a9f02ab55aa670a0393192722

SHA-1:
395fd7ee13ad7fd4c9fb1ce2346b0e083cb5f2ae

SHA-256:
3b01541b09701a24ef02110c6f8f6e2d59f04b6eadc6bd18081324d7583105ca

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/16/2024 5:22:56 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Hao123.H potentially unwanted application
6.3.12010.0

File size:
3.8 MB (3,966,096 bytes)

Product version:
3.3.1.6

Original file name:
KBrowser.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\hbrowser\kbrowser.exe

Digital Signature
Signed by:

Authority:
WoSign CA Limited

Valid from:
10/19/2015 2:58:10 PM

Valid to:
11/19/2016 2:58:10 PM

Subject:
CN=Liu Hang, E=xianip@163.com, L=Wuhan, S=Hubei, C=CN

Issuer:
CN=WoSign Class 2 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
3B6534A7146119DFC9EF50A70F2EDE84

File PE Metadata
Compilation timestamp:
8/29/2016 8:46:03 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:rLB4BI9HmcOEzjBEzDShlMqDfAAKfSMqDfAAK67YLYONCcz:/B4Bqmc73BuSzDIAKMDIAK67YLYWCcz

Entry address:
0x14D707

Entry point:
E8, A8, 0D, 01, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 0C, A1, 40, 2C, 5D, 00, 33, C5, 89, 45, FC, 56, 33, F6, 57, 3B, DE, 75, 1E, E8, 77, 32, 00, 00, 6A, 16, 5F, 56, 56, 56, 56, 56, 89, 38, E8, DC, AE, FF, FF, 83, C4, 14, 8B, C7, E9, 47, 01, 00, 00, FF, 75, 08, 53, E8, 8E, B0, FF, FF, 59, 59, 3B, 45, 08, 72, 07, 33, C0, 66, 89, 03, EB, CB, 8B, 55, 0C, 8B, 02, 8B, 48, 14, 3B, CE, 75, 2A, 8B, C3, 66, 39, 33, 74, 1C, 0F, B7, 08, 66, 83, F9, 61, 72, 0C, 66, 83, F9, 7A, 77, 06, 83, C1, E0, 66, 89...
 
[+]

Entropy:
6.9918

Code size:
1.5 MB (1,531,392 bytes)

Shell Open Command
Open type:
htmlfile

Command:
"C:\users\{user}\appdata\roaming\hbrowser\kbrowser.exe" "%1"


Scan KBrowser.exe - Powered by Reason Core Security