kingoroot.exe

Win

Microsoft

This is a setup program which is used to install the application. The file has been seen being downloaded from www.filetowerfun.com.
Publisher:
Microsoft

Product:
Win

Version:
1.00

MD5:
3f840fee630bf902df87ab7d07c30a7b

SHA-1:
327ef8f66939e90d3412b4a62405e2010acac691

SHA-256:
06e624614e33d292c934f8a13ad4257414cb767120e5d54fb3ddf38d5ab114b4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2025 11:59:53 PM UTC  (a few moments ago)

File size:
1.3 MB (1,344,728 bytes)

Product version:
1.00

Original file name:
Win.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\kingoroot.exe

File PE Metadata
Compilation timestamp:
10/5/2012 3:38:39 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:ILge4x02Y3FsHGdvaFku55rW6AkCOufUTHocQa7/nJor7F5HPxkmoqie2:ZW2LGBM5syuf8FQa7nJor7Fkmoqie2

Entry address:
0x36A0

Entry point:
F3, C6, C1, 11, 4B, B8, C3, 9E, 41, EA, 81, D5, 99, 54, 26, A1, FE, CE, 0F, AF, DF, 8D, 3D, 49, 8A, 48, AB, 85, C9, 2C, 1B, 55, 57, F6, C5, B7, 48, E8, 10, 00, 00, 00, F3, F7, C0, BC, DA, 8B, 45, 2D, 51, 93, CE, 04, 85, D3, 3B, E8, 8D, 05, D5, E8, FF, 41, 89, D8, 81, DE, 9F, 57, 3B, 41, 88, EC, 84, D8, 84, D6, 81, FD, F7, CB, 00, 00, 5E, 77, 07, 0F, B7, DB, 4B, 0F, BF, CF, 13, DA, 8A, CE, F6, C2, 38, FF, C1, 4F, 25, 48, E7, 27, 75, FE, C2, 89, C9, 86, C9, 81, C3, BE, C4, 00, 00, 8B, CE, 81, C3, 2D, 03, 00...
 
[+]

Entropy:
7.8086  (probably packed)

Code size:
172 KB (176,128 bytes)

The file kingoroot.exe has been seen being distributed by the following URL.

Scan kingoroot.exe - Powered by Reason Core Security