tch_xas_v176.exe

TODO: <产品名>

TODO: <公司名>

This is a setup program which is used to install the application. The file has been seen being downloaded from airlcs.gotoip3.com.
Publisher:
TODO: <公司名>

Product:
TODO: <产品名>

Description:
TODO: <文件说明>

Version:
1.0.0.1

MD5:
892daf69741860dd6ebe285e51c4725a

SHA-1:
d30c65e65a06f90e47f1faa6ff5979b0062d3c82

SHA-256:
dc196c7a8e911c18b9531cff99d75a060c02dab75bf7add0b4c075b86c215481

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:14:26 AM UTC  (today)

File size:
2.7 MB (2,870,272 bytes)

Product version:
1.0.0.1

Copyright:
TODO: (C) <公司名>。保留所有权利。

Original file name:
Tch_xA.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\tch_xas_v176.exe

File PE Metadata
Compilation timestamp:
5/13/2016 10:00:49 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:NkBA6eDmshgzgTgs+spmCFpeJni3k/OOm/Hc+on5lJTzRSpQaI3WGY1piu31GM11:K2NimzTgdsMiCOFP0YMWjpTIw

Entry address:
0x5191AF

Entry point:
E8, 52, 6F, 01, 00, 54, C6, 04, 24, FE, 8D, 64, 24, 08, 0F, 84, E6, CC, DA, FF, 60, 50, FF, 74, 24, 04, FF, 34, 24, 89, C6, 98, 9C, 8D, 04, CD, 98, E3, 6E, F8, 89, 5C, 24, 2C, 0F, 94, C4, 8D, 05, 8C, B0, 6B, 00, C6, 04, 24, 29, FF, 74, 24, 04, E9, 0A, 4E, 01, 00, 75, C1, A3, BF, 62, E0, 8C, F3, A2, BC, 52, EC, 22, 22, CD, 73, 79, C1, 20, 28, AC, 98, 57, F5, 0B, 25, DF, E7, 8E, BC, 36, 02, C1, 8D, 42, 1E, 14, 4B, 5F, 9E, 30, B1, 60, F4, 33, 0F, AC, 86, 35, 15, D2, AC, FF, AE, 8E, 41, 17, 23, 30, 01, 45, F0...
 
[+]

Entropy:
7.8791  (probably packed)

Code size:
248.5 KB (254,464 bytes)

The file tch_xas_v176.exe has been seen being distributed by the following URL.

Scan tch_xas_v176.exe - Powered by Reason Core Security