kingoroot.exe

Didoruro

Kekahabeda

This is a setup and installation application. The file has been seen being downloaded from www.filetowerfun.com.
Publisher:
Kekahabeda

Product:
Didoruro

Description:
Didoruro Setup

Version:
1.1.1.0

MD5:
4f65e7d9cebb68f473e1dded7491afa9

SHA-1:
e84b66fe603cb0d988958d768049ebb6f8d863db

SHA-256:
1a246cdc363f63b3226401fbdca97607330a88ba2a198da97472ba6ce7576905

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 12:40:39 PM UTC  (today)

File size:
1.1 MB (1,123,264 bytes)

Product version:
5.1.7

Copyright:
Wizard Installer

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\kingoroot.exe

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:pKNo0gNhcuCTk1MIMVZtbtzC2KB/cXiwH0WyR2+KXvy0T+x+5aaeDjAXh7:p6ovhc1I1ZIZV5fvSwH0lM+atyxuat/s

Entry address:
0xAA98

Entry point:
11, DF, 0F, AF, D7, 8D, 05, 4E, 3E, B3, 32, 8D, 0D, E3, 87, FE, FD, 76, 0A, 28, C5, 69, EA, 76, 00, 97, 9A, F7, DA, 89, C6, BA, 53, 83, F8, FF, F7, D5, 81, F2, 3E, 70, 00, 00, 8D, 0D, 77, 4A, B3, 83, 81, EA, DC, 0C, 00, 00, 46, 81, FF, 09, E8, 00, 00, 74, 07, 1B, F6, 0F, CD, 0F, AF, EF, 08, EC, BB, 4F, F7, FF, FF, 69, C0, 13, 73, 07, A3, 81, C3, B1, 08, 00, 00, 01, DE, 33, DA, 84, EC, 81, C3, 70, 03, 02, 00, C6, C2, 06, 03, FB, 89, D1, 81, C7, 6C, 78, 05, 00, 8B, EA, 76, 04, 03, FF, 8B, DE, 89, CB, E8, 0C...
 
[+]

Entropy:
7.9285  (probably packed)

Code size:
40.5 KB (41,472 bytes)

The file kingoroot.exe has been seen being distributed by the following URL.

Scan kingoroot.exe - Powered by Reason Core Security