qhtsft64.exe

Quick Heal AntiVirus

Quick Heal Technologies (Pvt) Ltd.

This is a self-extracting archive and installer. The file has been seen being downloaded from quick-heal-total-security.soft32.com.
Publisher:
Quick Heal Technologies (P) Ltd.  (signed by Quick Heal Technologies (Pvt) Ltd.)

Product:
Quick Heal AntiVirus

Description:
Installer Application

Version:
7.0.0.1

MD5:
43842dede113f12e67452f5a987ac1cb

SHA-1:
ebc449ebe83152bd1d8192132fa70f33f255276f

SHA-256:
be987a476dbf0e6cfc007501fcfdf04c3930d4abe8a66905a8ca2afab75cef8f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:27:38 PM UTC  (today)

File size:
272.7 MB (285,968,648 bytes)

Product version:
14.00

Copyright:
© Quick Heal Technologies (P) Ltd. All rights reserved.

Original file name:
qhunpack.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\qhtsft64.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/21/2010 5:30:00 AM

Valid to:
9/24/2013 5:29:59 AM

Subject:
CN=Quick Heal Technologies (Pvt) Ltd., OU=R & D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Quick Heal Technologies (Pvt) Ltd., L=Pune, S=Maharashtra, C=IN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
720B545D558CEF7F6758A5FBB8429A9F

File PE Metadata
Compilation timestamp:
9/4/2012 6:40:11 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6291456:R+tsh5zp8IStZIRa9QFc/U71qkN/TVXkVIyA9ysKWK+9GU+7p4utyCTWKZG:R+tO5zpAAfYU1N91600sX+7p4cDTTZG

Entry address:
0x72E0

Entry point:
48, 83, EC, 28, E8, 3B, 4F, 00, 00, 48, 83, C4, 28, E9, 16, FE, FF, FF, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, E9, E5, 00, 00, FF, 15, 23, 7F, 00, 00, 4C, 8B, 1D, D4, E6, 00, 00, 4C, 89, 5C, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, AD, 77, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24, 50, 00, 74, 41, 48, C7, 44, 24, 38, 00, 00, 00, 00, 48, 8D, 44, 24, 48, 48, 89, 44, 24, 30, 48, 8D, 44, 24, 40, 48, 89, 44, 24, 28, 48, 8D, 05, 94, E5, 00, 00, 48, 89, 44, 24...
 
[+]

Entropy:
7.9796  (probably packed)

Code size:
55.5 KB (56,832 bytes)

The file qhtsft64.exe has been seen being distributed by the following URL.