tuiexe_ipad_1.0.0_32.exe

Tongbutui

Xiamen Tongbu Networks Ltd.

Publisher:
Xiamen Tongbu Networks Co., Ltd.  (signed by Xiamen Tongbu Networks Ltd.)

Product:
Tongbutui

Version:
2.0.1.0

MD5:
dd39f62e4e953c8eb0c59859a2ea1332

SHA-1:
07a9a5b1d134d68ae8c21c92ff1909a0dfc3359c

SHA-256:
c983b4edf0e9760deca44a92236dfa37073b706c548d782ba9d4cf310e3dd0d3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 4:41:14 AM UTC  (today)

File size:
19.2 MB (20,145,368 bytes)

Product version:
2.0.1.0

Copyright:
Copyright (c) Tongbu Networks Co., Ltd.

Original file name:
ipa2exe.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\tuiexe_ipad_1.0.0_32.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/28/2016 8:00:00 AM

Valid to:
6/28/2019 7:59:59 AM

Subject:
CN=Xiamen Tongbu Networks Ltd., OU=PC, O=Xiamen Tongbu Networks Ltd., L=Xiamen, S=Fujian, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
32D38ABDDE438F817297BE458EFB4CD4

File PE Metadata
Compilation timestamp:
6/7/2016 5:12:53 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
393216:TKs+7P0fmKs+7P0fXloVw51KLl+rPJFmFXohF/dWU:TKsAP0OKsAP0fSI+QzJI5ov/1

Entry address:
0x30F8FD

Entry point:
E8, 94, 23, 01, 00, E9, 39, FE, FF, FF, FF, 35, 54, 46, 89, 00, FF, 15, 30, 46, 77, 00, C3, FF, 35, 54, 46, 89, 00, FF, 15, 30, 46, 77, 00, 85, C0, 74, 02, FF, D0, 6A, 01, 6A, 00, E8, DC, 93, 00, 00, 59, 59, E9, F4, 93, 00, 00, 55, 8B, EC, 56, FF, 35, 54, 46, 89, 00, FF, 15, 30, 46, 77, 00, FF, 75, 08, 8B, F0, FF, 15, 8C, 44, 77, 00, A3, 54, 46, 89, 00, 8B, C6, 5E, 5D, C3, 56, 6A, 04, 6A, 20, E8, FD, 2C, 01, 00, 59, 59, 8B, F0, 56, FF, 15, 8C, 44, 77, 00, A3, 10, 4B, 89, 00, A3, 0C, 4B, 89, 00, 85, F6, 75...
 
[+]

Entropy:
7.5747

Code size:
3.4 MB (3,616,256 bytes)

The file tuiexe_ipad_1.0.0_32.exe has been seen being distributed by the following URL.

Scan tuiexe_ipad_1.0.0_32.exe - Powered by Reason Core Security