reason_极速安装.exe

91助手在线安装器

福建博瑞网络科技有限公司

Publisher:
福州博远无线网络科技有限公司  (signed by 福建博瑞网络科技有限公司)

Product:
91助手在线安装器

Version:
1, 0, 1, 13

MD5:
5756af051f2b26403c898e412bdc0dde

SHA-1:
457526231e8fddb347d22a8ffb66d72625076440

SHA-256:
c2b98956e2f64d97a8f2856157141f77c878cfeefc9307b0e95a939a64cf8151

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 12:37:06 AM UTC  (today)

File size:
825.3 KB (845,088 bytes)

Product version:
1, 0, 1, 13

Copyright:
Copyright (C) 2012 福州博远无线网络科技有限公司

Original file name:
OnlineInst.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\reason_极速安装.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/11/2014 8:00:00 AM

Valid to:
6/11/2017 7:59:59 AM

Subject:
CN=福建博瑞网络科技有限公司, O=福建博瑞网络科技有限公司, L=福州, S=福建省, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
040DB82E8ADBA06DC37D196316891F97

File PE Metadata
Compilation timestamp:
3/8/2016 4:14:09 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:pgVdzkULumfhdVummhJWTcrw03mpBnPHCKFfzhO3JD4iGk1i86SHyFJ5ZTI6:tirahYTcrn2pBnPPFfsD4iGk1nSFJ

Entry address:
0x384D2

Entry point:
E8, 91, 04, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, E8, 71, 45, 00, 89, 0D, E4, 71, 45, 00, 89, 15, E0, 71, 45, 00, 89, 1D, DC, 71, 45, 00, 89, 35, D8, 71, 45, 00, 89, 3D, D4, 71, 45, 00, 66, 8C, 15, 00, 72, 45, 00, 66, 8C, 0D, F4, 71, 45, 00, 66, 8C, 1D, D0, 71, 45, 00, 66, 8C, 05, CC, 71, 45, 00, 66, 8C, 25, C8, 71, 45, 00, 66, 8C, 2D, C4, 71, 45, 00, 9C, 8F, 05, F8, 71, 45, 00, 8B, 45, 00, A3, EC, 71, 45, 00, 8B, 45, 04, A3, F0, 71, 45, 00, 8D, 45, 08, A3, FC, 71, 45...
 
[+]

Entropy:
6.8503

Code size:
242.5 KB (248,320 bytes)

The file reason_极速安装.exe has been seen being distributed by the following URL.

Scan reason_极速安装.exe - Powered by Reason Core Security