ttkansvr.exe

北京天创奇迹广告有限公司

It runs as a windows Service named “ttkanservice”.
Publisher:
北京天创奇迹广告有限公司  (signed and verified)

MD5:
174b12c054b7a5c5ba2ef06148fa9c77

SHA-1:
991d68c47b82cfb24ab7fd00d092a4ce6f7e5ce4

SHA-256:
cc4aab4a4f3233a00a993f6c1494c286db6c40b6949346df14e11a46b1740d28

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:04:27 AM UTC  (today)

File size:
556.6 KB (570,008 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/14/2012 8:00:00 AM

Valid to:
9/13/2013 7:59:59 AM

Subject:
CN=北京天创奇迹广告有限公司, OU=北京天创奇迹广告有限公司, O=北京天创奇迹广告有限公司, L=beijing, S=beijing, C=CN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
20D82BAC683325FBE0B262B28E439C49

File PE Metadata
Compilation timestamp:
9/13/2012 4:37:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x71864

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 50, 0A, 47, 00, E8, 5B, 53, F9, FF, A1, A0, 3C, 47, 00, 8B, 00, 80, 78, 30, 00, 74, 10, A1, A0, 3C, 47, 00, 8B, 00, E8, 1E, 3B, FF, FF, 84, C0, 74, 0C, A1, A0, 3C, 47, 00, 8B, 00, 8B, 10, FF, 52, 34, 8B, 0D, F4, 3C, 47, 00, A1, A0, 3C, 47, 00, 8B, 00, 8B, 15, 8C, 08, 47, 00, 8B, 18, FF, 53, 30, A1, A0, 3C, 47, 00, 8B, 00, 8B, 10, FF, 52, 38, 5B, E8, E8, 30, F9, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6388

Developed / compiled with:
Microsoft Visual C++

Code size:
450 KB (460,800 bytes)

Service
Display name:
ttkanservice

Type:
Win32OwnProcess, InteractiveProcess


Scan ttkansvr.exe - Powered by Reason Core Security