r-angel-windows.exe

복구천사 Windows Recovery

LLC SysDev Laboratories

Publisher:
SysDev Laboratories Korea Co. Ltd  (signed by LLC SysDev Laboratories)

Product:
복구천사 Windows Recovery

Version:
6.8.0.4278

MD5:
6b9be9137482d4f958387df4eea39a8e

SHA-1:
49c575a78e8316b56e838514f0b1917a7dc44d15

SHA-256:
cc343baf952f26b8f61770383fb42510dcaacb22691afc3d72d158910d4078b9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 12:53:59 PM UTC  (today)

File size:
5 MB (5,221,944 bytes)

Product version:
6.8.0.1

Copyright:
Copyright (C) 2004-2016 Bogdan Shulga (LLC SysDev Laboratories)

Original file name:
rangel-win.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\복구천사\r-angel-windows.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
3/16/2016 9:00:00 AM

Valid to:
9/20/2016 8:59:59 AM

Subject:
CN=LLC SysDev Laboratories, O=LLC SysDev Laboratories, L=Donetsk, S=Donetsk Oblast, C=UA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
54A4321E51EA5920E59ADD72A731F485

File PE Metadata
Compilation timestamp:
9/8/2016 6:35:29 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:HEpdhNEeg4NJ5hAmAKWIY+loEsPG9OF7lpm6RjLzIGQpI:sheetJQmAKWisPJFTnRTIGX

Entry address:
0x1A5C02

Entry point:
E8, 86, 53, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 78, BF, 8B, 00, FF, 15, 18, C2, 67, 00, 85, C0, 75, 18, 56, E8, 38, 54, 00, 00, 8B, F0, FF, 15, A4, C0, 67, 00, 50, E8, E8, 53, 00, 00, 59, 89, 06, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 78, BF, 8B, 00, 00, 75, 18, E8, 7C, 3D, 00, 00, 6A, 1E, E8, C6, 3B, 00, 00, 68, FF, 00, 00, 00, E8, C9, 42, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40...
 
[+]

Entropy:
6.6678

Code size:
2.5 MB (2,600,448 bytes)

Scan r-angel-windows.exe - Powered by Reason Core Security