onekeyghost64.exe

OneKey Ghost

OneKey.Cc

This is a setup program which is used to install the application. The file has been seen being downloaded from doc-0k-bo-docs.googleusercontent.com and multiple other hosts.
Publisher:
OneKey.Cc

Product:
OneKey Ghost

Description:
一键还原

Version:
6.5.11.173

MD5:
d9db32bb8a6f1a45adc81e63633b6cee

SHA-1:
cd21beca26b6c4d3dba7714e163d8e4362033f1b

SHA-256:
ee259e2e18d25ffc73327eac17c9dd3f36845593f2cead55f4667a4259b1a35b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 11:28:45 AM UTC  (today)

File size:
3.8 MB (4,035,180 bytes)

Copyright:
Copyright (C) 2005-2011 OneKey.Cc

Trademarks:
OneKey Ghost

Original file name:
OneKeyGhost.exe

File type:
Executable application (Win64 EXE)

Language:
Chinese (Simplified, PRC)

File PE Metadata
Compilation timestamp:
4/16/2010 2:47:52 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:42EjXHQsW/PN+Qf9zSOUTwCP/bJNILkwXU+eYLPj7BVES91mrWQxmE+0/7IW0vw/:4rQ7dM5cizJNFjij7BH91mSQxpGwH

Entry address:
0x1D47C

Entry point:
48, 83, EC, 28, E8, E7, C0, 00, 00, 48, 83, C4, 28, E9, 1A, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 4D, 85, C0, 74, 75, 48, 2B, D1, 4C, 8B, CA, 49, BB, 00, 01, 01, 01, 01, 01, 01, 81, F6, C1, 07, 74, 1F, 8A, 01, 42, 8A, 14, 09, 48, FF, C1, 3A, C2, 75, 57, 49, FF, C8, 74, 4E, 84, C0, 74, 4A, 48, F7, C1, 07, 00, 00, 00, 75, E1, 4A, 8D, 14, 09, 66, 81, E2, FF, 0F, 66, 81, FA, F8, 0F, 77, D1, 48, 8B, 01, 4A, 8B, 14, 09, 48, 3B, C2, 75, C5, 48, 83, C1, 08, 49, 83, E8...
 
[+]

Entropy:
7.8762  (probably packed)

Code size:
599 KB (613,376 bytes)

The file onekeyghost64.exe has been seen being distributed by the following 2 URLs.

https://doc-0k-bo-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/253g8kj22ss1fr16dprnnosfm8big50n/1484186400000/04637137776297170082/.../0B_Q1hk1sq-jBdVUwMThRWFBsUUE?e=download

Scan onekeyghost64.exe - Powered by Reason Core Security