tch_xa_v161.exe

TODO: <产品名>

TODO: <公司名>

This is a setup program which is used to install the application. The file has been seen being downloaded from airlcs.gotoip3.com.
Publisher:
TODO: <公司名>

Product:
TODO: <产品名>

Description:
TODO: <文件说明>

Version:
1.0.0.1

MD5:
64530fc2fa80ce0ec5a05c53632d071c

SHA-1:
6dd3e834a3ee751bebceda8bacc734575db1f1eb

SHA-256:
4debd4b8b84863379c5322a7487e8356e41545cf760632d25340f46009318042

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 3:46:49 AM UTC  (today)

File size:
2.8 MB (2,886,144 bytes)

Product version:
1.0.0.1

Copyright:
TODO: (C) <公司名>。保留所有权利。

Original file name:
Tch_xA.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\users\{user}\downloads\programs\tch_xa_v161.exe

File PE Metadata
Compilation timestamp:
1/14/2016 1:57:55 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:W0ZhI3Vm6rUd3jM6tr+sAwVjGqeo46Yymiwl2UJxQSkbCPbPrkbrOAzmc0AgS9fC:Te3VmUU5Q67Aw5jeoCasGS7bvAyc0Axd

Entry address:
0x54AFDC

Entry point:
50, E8, 09, 79, FF, FF, 47, 9C, 88, 1C, 24, 88, 0C, 24, 8D, 64, 24, 08, E9, 06, 26, FF, FF, C7, 44, 24, 3C, B7, 13, 95, 00, 68, 98, 1A, 10, AE, FF, 30, 8F, 44, 24, 3C, 57, 88, 44, 24, 04, FF, 74, 24, 40, C2, 44, 00, 88, C9, DD, 27, 6C, 43, 65, BA, 88, 5C, D5, 33, 32, 4D, 79, B7, 29, AD, 3D, 76, 57, 99, 49, D3, 7B, B3, 0A, 39, 69, 88, 6D, E6, 24, 02, 65, 09, A7, 6F, B2, 26, 7B, D3, FA, 4D, F5, 42, EB, 49, CE, 7C, A9, 5D, 45, EA, 32, FA, 90, EA, D1, 76, BE, 88, 06, BA, 74, F2, CB, E6, 6B, 6F, 58, EF, 62, 89...
 
[+]

Entropy:
7.8610  (probably packed)

Code size:
248.5 KB (254,464 bytes)

The file tch_xa_v161.exe has been seen being distributed by the following URL.

Scan tch_xa_v161.exe - Powered by Reason Core Security