lhasa020.exe

Lhasa Installer

Yoshihito Takemura

Publisher:
Takechin  (signed by Yoshihito Takemura)

Product:
Lhasa Installer

Version:
0, 20, 0, 0

MD5:
4dee3f1d7b66448d42e48a2db4611bde

SHA-1:
82f2bb6e2ad88092f950c8020569db01a3c5aa61

SHA-256:
9006f4e77865ff06637664b5f49edce0fcada7a912ef1e45054c8aa7a2a397f2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 5:49:46 AM UTC  (today)

File size:
116.4 KB (119,152 bytes)

Product version:
0, 20, 0, 0

Copyright:
Copyright (C) 1994-2002 Takechin

Original file name:
Lhasains.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\lhasa020.exe

Digital Signature
Authority:
StartCom Ltd.

Valid from:
1/24/2010 6:11:29 PM

Valid to:
1/26/2012 7:41:44 AM

Subject:
E=takechin@digitalpad.co.jp, CN=Yoshihito Takemura, OU=StartCom Verified Certificate Member, L=Suginami-ku, S=Tokyo, C=JP, Description=134797-d5aBsLKFWgU336v9

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
00AB

File PE Metadata
Compilation timestamp:
10/10/2010 10:37:19 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
3072:kqWzX62Ll5g02j38yBbAg8IO3lrdVHEdF:kqw6dMCbjeoF

Entry address:
0x28C7

Entry point:
6A, 60, 68, 80, 72, 40, 00, E8, 3D, 0E, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 91, 0F, 00, 00, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, CC, 70, 40, 00, 8B, 4E, 10, 89, 0D, EC, 93, 40, 00, 8B, 46, 04, A3, F8, 93, 40, 00, 8B, 56, 08, 89, 15, FC, 93, 40, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, F0, 93, 40, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, F0, 93, 40, 00, C1, E0, 08, 03, C2, A3, F4, 93, 40, 00, 33, F6, 56, 8B, 3D, C0, 70, 40, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
7.0701

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
24 KB (24,576 bytes)

The file lhasa020.exe has been seen being distributed by the following 7 URLs.

http://dforest.watch.impress.co.jp/library/l/lhasa/.../Lhasa020.exe

http://www.dlsite.com/modpub/.../lhasa020.exe

http://ftp.vector.co.jp/pack/win95/util/.../Lhasa020.exe

Scan lhasa020.exe - Powered by Reason Core Security