StSess.exe

AhnLab Safe Transaction

AhnLab, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘AhnLab Safe Transaction Application’.
Publisher:
AhnLab, Inc.  (signed and verified)

Product:
AhnLab Safe Transaction

Description:
AhnLab Safe Transaction Application

Version:
1, 0, 0, 347

MD5:
8a5c1e2ba2f354eb0ceb6097f9b27eae

SHA-1:
98a81ddfd416e22569af37c5fd629d5ab176cf3a

SHA-256:
6e0ed8d52dd5d09619171c21096e74c1c2d5b24fa1a5897a3d143e792c5dd1e9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 5:53:18 AM UTC  (today)

File size:
2.4 MB (2,497,256 bytes)

Product version:
1, 0, 0, 2

Copyright:
Copyright (C) AhnLab, Inc. 1988-2015. All rights reserved.

Original file name:
StSess.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ahnlab\safe transaction\stsess.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/31/2014 9:00:00 AM

Valid to:
4/1/2016 8:59:59 AM

Subject:
CN="AhnLab, Inc.", O="AhnLab, Inc.", L=Seongnam, S=Gyeounggi, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
460DBFED46F7D23930BF0C3A1ED335B7

File PE Metadata
Compilation timestamp:
1/8/2016 6:13:55 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x163EEC

Entry point:
E8, 47, 06, 00, 00, E9, 37, FD, FF, FF, 3B, 0D, 14, 07, 5F, 00, 75, 02, F3, C3, E9, C9, 06, 00, 00, 6A, 14, 68, 48, 86, 5D, 00, E8, 13, 03, 00, 00, FF, 35, B8, 0E, 61, 00, 8B, 35, CC, 15, 58, 00, FF, D6, 59, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, D0, 15, 58, 00, 59, EB, 67, 6A, 08, E8, A5, 07, 00, 00, 59, 83, 65, FC, 00, FF, 35, B8, 0E, 61, 00, FF, D6, 89, 45, E4, FF, 35, B4, 0E, 61, 00, FF, D6, 59, 59, 89, 45, E0, 8D, 45, E0, 50, 8D, 45, E4, 50, FF, 75, 08, 8B, 35, E4, 15, 58, 00, FF, D6, 59...
 
[+]

Entropy:
6.4768

Code size:
1.5 MB (1,570,304 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AhnLab Safe Transaction Application

Command:
"C:\Program Files\ahnlab\safe transaction\stsess.exe" \tray


Scan StSess.exe - Powered by Reason Core Security