rxzg-az-slrx.exe

wjtx Lander

趣游时代(北京)科技有限公司

This is a setup program which is used to install the application. The file has been seen being downloaded from cdn.pkg.tonnn.com.
Publisher:
江西中至科技有限公司  (signed by 趣游时代(北京)科技有限公司)

Product:
wjtx Lander

Description:
2217-武极天下微端

Version:
1.0.0.0

MD5:
2928d13e99bf23f26690fb34e1b77e4b

SHA-1:
903efb8b727e00f3232223380b4e48eeaf7e44c3

SHA-256:
118d109a31ff2372ba0d0e529914d17c45dd61b38534c839375e00f6a2001314

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 3:00:21 AM UTC  (today)

File size:
2.9 MB (3,010,672 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (C) 2016 2217游戏 www.2217.com 江西中至科技有限公司

Original file name:
wjtx Lander

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\rxzg-az-slrx.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
4/7/2016 1:37:34 PM

Valid to:
7/7/2017 1:37:34 PM

Subject:
CN=趣游时代(北京)科技有限公司, O=趣游时代(北京)科技有限公司, L=北京市, S=北京市, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
2674612888778CD8E2B4B798C1D844D1

File PE Metadata
Compilation timestamp:
4/28/2016 10:31:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:zqe3x8KEr47ad8jMP0SpKoyV8WGniwqdj3tmo9xmnoQHVAUqCmjoQKx18khoW:zZ3OKnY8jMPP49V8JiwqZdD9xmowVAUT

Entry address:
0x420D

Entry point:
E8, 46, 05, 00, 00, E9, 37, FD, FF, FF, 6A, 14, 68, 48, 58, 40, 00, E8, B9, 00, 00, 00, FF, 35, 78, 76, 40, 00, 8B, 35, 5C, 51, 40, 00, FF, D6, 59, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, 58, 51, 40, 00, 59, EB, 67, 6A, 08, E8, AD, 05, 00, 00, 59, 83, 65, FC, 00, FF, 35, 78, 76, 40, 00, FF, D6, 89, 45, E4, FF, 35, 74, 76, 40, 00, FF, D6, 59, 59, 89, 45, E0, 8D, 45, E0, 50, 8D, 45, E4, 50, FF, 75, 08, 8B, 35, 44, 51, 40, 00, FF, D6, 59, 50, E8, 70, 05, 00, 00, 89, 45, DC, FF, 75, E4, FF, D6, A3...
 
[+]

Entropy:
7.9080  (probably packed)

Code size:
15 KB (15,360 bytes)

The file rxzg-az-slrx.exe has been seen being distributed by the following URL.

Scan rxzg-az-slrx.exe - Powered by Reason Core Security