uni1795887c.exe

Beijing Rising Information Technology Corporation Limited

This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RavDown’. The file has been seen being downloaded from k.rising.com.cn.
MD5:
8a86c28fed111f3b697cad1c834e038a

SHA-1:
a41e929c8041a4f1131055fe4f6a195d7effe1ec

SHA-256:
c60834590e17a80dae92855ac904e5b28f4066778114a5cf69c6eb211785ea98

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 11:58:17 AM UTC  (today)

File size:
148.2 KB (151,736 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\uni1795887c.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/31/2015 9:00:00 AM

Valid to:
9/8/2018 8:59:59 AM

Subject:
CN=Beijing Rising Information Technology Corporation Limited, O=Beijing Rising Information Technology Corporation Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
488002CAF3616BEEEE4C045BD69978D7

File PE Metadata
Compilation timestamp:
3/17/2014 2:46:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:G8W1Bd8kPUqrXx7tE6a5rWMnsKHWQbL+o3o7I4gWHDI/x+5zzzzzea:pW1QBWXx7to5iMnHjv3o7IGjYg5zzzzJ

Entry address:
0x48F30

Entry point:
60, BE, 00, B0, 42, 00, E9, B2, 01, 00, 00, 90, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8870  (probably packed)

Code size:
124 KB (126,976 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RavDown

Command:
"C:\users\{user}\appdata\local\temp\{random}.tmp\uni1795887c.exe" \session 25acc68da78641a6b507d4dc63ba68fd \subkey rav


The file uni1795887c.exe has been seen being distributed by the following URL.

Scan uni1795887c.exe - Powered by Reason Core Security