tch_xa_v160.exe

TODO: <产品名>

TODO: <公司名>

This is a setup program which is used to install the application. The file has been seen being downloaded from airlcs.gotoip3.com.
Publisher:
TODO: <公司名>

Product:
TODO: <产品名>

Description:
TODO: <文件说明>

Version:
1.0.0.1

MD5:
bddf2deea003db13d1c580e6be3198a0

SHA-1:
6207135bd9e9ac5cfcedb0f7099631ff1ab1221a

SHA-256:
e14e6aca8acfbd85179217bbedab79975d74949fc5d73e6fd2c209b24f7e2d0f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:13:58 AM UTC  (today)

File size:
2.6 MB (2,762,240 bytes)

Product version:
1.0.0.1

Copyright:
TODO: (C) <公司名>。保留所有权利。

Original file name:
Tch_xA.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\tch_xa_v160.exe

File PE Metadata
Compilation timestamp:
1/7/2016 12:03:49 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:UKIbedQrSSKMJhVLpUOCdrmyXEDKDlSTF0GqadmCy8ObT0jNvxrqYVfK+Az1+rG1:UK0edSSOvVUTbwKDlAEadmCfObTgvxrO

Entry address:
0x51FF2C

Entry point:
E9, 79, CC, FB, FF, F4, 8E, 0A, 73, 46, 0B, 2F, 9F, C5, E4, AA, ED, 87, 9E, D4, E4, 21, 34, 82, 19, 47, 8C, 57, 29, 6D, 0B, 4E, 17, 5B, 67, FC, 45, 06, 9E, 25, F3, 07, 6F, 63, A0, 8A, F0, C5, 0E, CF, E9, 21, 3B, 33, 04, 77, C1, 75, 2E, C8, 0A, A6, 24, 41, D6, AB, F4, B5, 51, BE, E4, FD, B9, DF, 13, 47, EE, 37, 47, DF, 4B, 41, F5, 05, A5, 5D, 30, 25, 87, 1C, 9F, B7, 54, FE, 4B, 1C, B9, 08, 76, 0E, 7C, B0, 77, 2C, EA, D5, EE, 08, 1E, B7, 48, 83, B7, 9A, 66, 6C, E1, F3, C5, 03, C4, F9, 6C, 22, C1, 5A, 01, 99...
 
[+]

Entropy:
7.8492

Packer / compiler:
Xtreme-Protector v1.05

Code size:
248.5 KB (254,464 bytes)

The file tch_xa_v160.exe has been seen being distributed by the following URL.

Scan tch_xa_v160.exe - Powered by Reason Core Security