KKPInstaller.exe

看看影音在线安装

Shenzhen Video Legend Network Technology Co.,Ltd.

Publisher:

Product:
看看影音在线安装

Version:
1, 0, 0, 43

MD5:
0602bac6560cd8ad1e0d115298def2d5

SHA-1:
e39b790b9c55194d39c5af0880bcbd904fc1a65f

SHA-256:
daa6b71375de0277513069d275eacecf0386105ceb737ad4d7f61449d0767dfb

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 12:27:18 PM UTC  (today)

File size:
368.5 KB (377,360 bytes)

Product version:
1, 0, 0, 43

Copyright:
Copyright (c) 2016 Shenzhen Video Legend Network Technology Co.,Ltd.

Trademarks:
Video Legend

Original file name:
KKPInstaller.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\kkpinstaller.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
10/28/2015 8:00:00 AM

Valid to:
10/28/2018 7:59:59 AM

Subject:
CN="Shenzhen Video Legend Network Technology Co.,Ltd.", OU=R&D, O="Shenzhen Video Legend Network Technology Co.,Ltd.", L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
2F45428F979B6FA35CF436C537FDC3C3

File PE Metadata
Compilation timestamp:
6/7/2016 6:25:06 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:jc8R4ijY2fg+Q5XYqX4BfBCcGAJL3EWrd+iP0o/cMQvTGu3dHTPgQ:QriXjQ5XYTBfBCcpJbEWrd9sDdHToQ

Entry address:
0x1FD7E

Entry point:
E8, 83, B0, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, 2A, D8, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, D4, 5D, 44, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, 68, 92, 44, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, DC, CA, 43, 00, 68, 00, 01, 00, 00, 53, FF, 15, 14, 72, 43, 00, 85, C0, 74, 08, 89, 3D, 68, 92, 44, 00, EB, 15, FF, 15, D0, 70, 43, 00, 83, F8, 78, 75, 0A, C7, 05, 68, 92, 44, 00, 02...
 
[+]

Entropy:
6.7821

Code size:
213.5 KB (218,624 bytes)

The file KKPInstaller.exe has been seen being distributed by the following URL.

Scan KKPInstaller.exe - Powered by Reason Core Security