wowtalk.exe

KINGSOFT JAPAN, INC.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘wowtalk’.
Publisher:
KINGSOFT JAPAN, INC.  (signed and verified)

MD5:
60cb445e69cd336f8f0f94df6a48eae6

SHA-1:
8444ffa73d327f073cbdad1d12344ae3a8324e39

SHA-256:
661a3dd3fb667b4228690e28ff2760075dd47f7c21113676be26d4cd0f4269e6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 9:11:22 AM UTC  (today)

File size:
58.4 MB (61,272,432 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\wowtalk\wowtalk.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/18/2016 6:57:28 PM

Valid to:
12/31/2016 3:25:00 PM

Subject:
E=codesign@kingsoft.jp, CN="KINGSOFT JAPAN, INC.", OU=Administration Division, O="KINGSOFT JAPAN, INC.", L=Minato-ku, S=Tokyo, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
048800C4C0D9BFD80364C176

File PE Metadata
Compilation timestamp:
7/29/2015 3:32:48 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x23646A8

Entry point:
48, 83, EC, 28, E8, 2F, A7, 01, 00, 48, 83, C4, 28, E9, 36, FE, FF, FF, CC, CC, 8B, 05, 8E, B9, 34, 01, 44, 8B, C2, 23, CA, 41, F7, D0, 44, 23, C0, 44, 0B, C1, 44, 89, 05, 79, B9, 34, 01, C3, 48, 83, EC, 28, E8, 33, 34, 00, 00, 48, 85, C0, 74, 0A, B9, 16, 00, 00, 00, E8, E8, 34, 00, 00, F6, 05, 59, B9, 34, 01, 02, 74, 29, B9, 17, 00, 00, 00, E8, F3, 9F, 6F, 00, 85, C0, 74, 07, B9, 07, 00, 00, 00, CD, 29, 41, B8, 01, 00, 00, 00, BA, 15, 00, 00, 40, 41, 8D, 48, 02, E8, 26, F6, FF, FF, B9, 03, 00, 00, 00, E8...
 
[+]

Entropy:
6.6456

Code size:
42.9 MB (44,977,664 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
wowtalk

Command:
"C:\Program Files\wowtalk\wowtalk.exe"


Scan wowtalk.exe - Powered by Reason Core Security