licenseextension30_kljeryk.exe

LicenseExtension4

K9

This is a setup program which is used to install the application. The file has been seen being downloaded from www.petel4school.com.
Publisher:
K9

Product:
LicenseExtension4

Version:
1.00

MD5:
d51f39c66c22b85188807cf8c30f1ab4

SHA-1:
d9ee544810f736aff7490dd2dd636529210355ed

SHA-256:
9bfdd0c8bdcf2a938ff1f37a75a2edb4ac111708aba10fcd02787a5d205a217f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/14/2024 2:01:40 AM UTC  (today)

File size:
125 KB (128,000 bytes)

Product version:
1.00

Original file name:
LicenseExtension30.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\licenseextension30_kljeryk.exe

File PE Metadata
Compilation timestamp:
6/17/2012 9:23:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:XA5aBokjnACMN9vzpYFKiK1TAaTOE2MoszABle+zTu:XXLte9rywibaTOE26zmo+2

Entry address:
0x5000

Entry point:
60, F8, 78, 01, 4F, 7D, 03, 66, D3, E9, 46, 78, 03, 79, 01, 76, F9, E9, 01, 00, 00, 00, 4B, BA, 5A, 51, 40, 00, E8, 01, 00, 00, 00, 7B, 83, 04, 24, 06, C3, E9, 01, 00, 00, 00, F8, 87, DF, C1, EB, F8, BE, 02, 33, 67, 4A, 0F, 86, 02, 00, 00, 00, 8B, E9, 81, F6, 17, EF, 19, 32, E8, 01, 00, 00, 00, EB, 83, C4, 04, E9, 08, 00, 00, 00, 66, 8B, DE, BF, 19, 97, F9, 47, 0F, 83, 02, 00, 00, 00, 87, FB, B9, 51, 00, 00, 00, E8, 01, 00, 00, 00, EA, 83, 04, 24, 06, C3, C1, EB, 6D, 0F, 85, 02, 00, 00, 00, 8B, FA, E9, 05...
 
[+]

Entropy:
7.6502

Code size:
8 KB (8,192 bytes)

The file licenseextension30_kljeryk.exe has been seen being distributed by the following URL.

Scan licenseextension30_kljeryk.exe - Powered by Reason Core Security