RlDateSet.exe

辅助程序

Tiangua (Shanghai) Information Technology Co., Ltd.

Publisher:
甜瓜(上海)信息技术有限公司  (signed by Tiangua (Shanghai) Information Technology Co., Ltd.)

Product:
辅助程序

Version:
1.0.0.0

MD5:
f8a99c9adb6e068ba08cbbb27ba59cf3

SHA-1:
ac9691ae7727809c59d3c0aac6075d1c1496f51a

SHA-256:
ba6efdce5ac2613c12386592bd99ab30cbd8bb7cc695660df94151cbd6bcaf8f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 5:56:34 AM UTC  (today)

File size:
939.8 KB (962,328 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (C) 2016

Original file name:
RlDateSet.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\rldateset.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
4/1/2016 8:00:00 AM

Valid to:
4/2/2018 7:59:59 AM

Subject:
CN="Tiangua (Shanghai) Information Technology Co., Ltd.", OU=Administration Department, O="Tiangua (Shanghai) Information Technology Co., Ltd.", L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
57F435713AB3A2C83F514AEDDE1D3DE0

File PE Metadata
Compilation timestamp:
3/18/2016 10:41:57 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:XChA3f+fTyrXSGjBbW8TSuaiQGbXyLqfSgbhB76vy/agnq:XChwf+yXLkEbf7zagq

Entry address:
0x8D550

Entry point:
E8, 1E, 04, 00, 00, E9, 6B, FD, FF, FF, FF, 25, 88, 13, 4C, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 18, E0, 4D, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, C0, 08, 4E, 00, 89, 0D, BC, 08, 4E, 00, 89, 15, B8, 08, 4E, 00, 89, 1D, B4, 08, 4E, 00, 89, 35, B0, 08, 4E, 00, 89...
 
[+]

Entropy:
6.7247

Code size:
768 KB (786,432 bytes)

The file RlDateSet.exe has been seen being distributed by the following 2 URLs.

http://41.223.201.248:801/.../RlDateSet.exe

Scan RlDateSet.exe - Powered by Reason Core Security