QueryStormSetup.exe

QueryStorm

Antonio Nakic Alfirevic

Publisher:
Windy Range Software  (signed by Antonio Nakic Alfirevic)

Product:
QueryStorm

Version:
1.6.265.1

MD5:
a2dd32902fe5388adab88ba3f5b1cd68

SHA-1:
9a58f79f62716a314c7caa1f99924be9826b7f4d

SHA-256:
5bf3eaea7089ccfe2a97aea2839892325163d0cb3d5e2839fa648e5130692d0a

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/28/2024 1:07:46 PM UTC  (today)

Scan engine
Detection
Engine version

Zillya! Antivirus
Trojan.Shelma.Win32.476
2.0.0.3159

File size:
567.4 KB (580,992 bytes)

Product version:
1.6.265.1

Copyright:
Copyright (c) Windy Range Software. All rights reserved.

Original file name:
QueryStormSetup.exe

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\del867b.tmp

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/28/2016 1:00:00 AM

Valid to:
1/28/2018 12:59:59 AM

Subject:
CN=Antonio Nakic Alfirevic, O=Antonio Nakic Alfirevic, STREET=Pujanke 36, STREET=Split, L=Split, S=Croatia, PostalCode=21000, C=HR

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009DC70CF34443B8D0D22414492F9EBBDF

File PE Metadata
Compilation timestamp:
6/7/2016 7:11:20 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x2E1AA

Entry point:
E8, C4, 04, 00, 00, E9, 80, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 08, 8B, 4C, 24, 10, 0B, C8, 8B, 4C, 24, 0C, 75, 09, 8B, 44, 24, 04, F7, E1, C2, 10, 00, 53, F7, E1, 8B, D8, 8B, 44, 24, 08, F7, 64, 24, 14, 03, D8, 8B, 44, 24, 08, F7, E1, 03, D3, 5B, C2, 10, 00, 55, 8B, EC, EB, 1F, FF, 75, 08, E8, 7D, 6C, 00, 00, 59, 85, C0, 75, 12, 83, 7D, 08, FF, 75, 07, E8, 13, 09, 00, 00, EB, 05, E8, EF, 08, 00, 00, FF, 75, 08, E8, F4, 6C, 00, 00, 59, 85, C0, 74, D4, 5D, C3, 55, 8B, EC...
 
[+]

Code size:
295 KB (302,080 bytes)

Scan QueryStormSetup.exe - Powered by Reason Core Security