File name:

KinhDown网盘增强工具.exe

Full analysis: https://app.any.run/tasks/ecde1ecb-b031-4d50-be71-49b15423ddde
Verdict: No threats detected
Analysis date: April 20, 2020, 03:22:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

40883729AFD4CB5F97EE44492ED47233

SHA1:

CF32793235394184C5E43B6C6E14AB0C80E9223C

SHA256:

090F7FF09FD4B2F26968CE314FD3272FB9E69C0EF2B51B10F4D48D25C32BE497

SSDEEP:

24576:lvGQaPbu6NL/K5TJ/p3RQ6C7NHLVuGTCMNv0YJk4rdtxmbQXD/8eNx+ijjkh4jju:lvG7Pbu6lep3Y7Nxd8qkpJj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (35.8)
.exe | Win64 Executable (generic) (31.7)
.scr | Windows screen saver (15)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:04:19 18:43:59+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 884736
InitializedDataSize: 393216
UninitializedDataSize: -
EntryPoint: 0xb367b
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
FileVersion: 1.0.0.0
FileDescription: KinhDown网盘增强工具
ProductName: KinhDown网盘增强工具
ProductVersion: 1.0.0.0
CompanyName: KinhUBAQ_Pro
LegalCopyright: 软件免责声明 1. 本软件仅供爱好者技术交流,请勿用于非法用途,如产生法律纠纷与开发者营运者无关。 2. 一切用户在下载并使用本软件时均被视为已经仔细阅读本声明并完全同意。凡以任何方式登录本软件,使用本软件者,均被视为自愿接受本软件相关声明和用户服务协议的约束。 3. 本软件只提供下载加速功能。 不提供任何下载资源及链接。用户使用本软件下载的内容并不代表本软件之意见及观点,也不代表本软件赞同用户的意图和观点。 4.用户使用本软件加速功能下载的所有资源,其真实性、准确性和合法性由资源发布人和用户本人负责。 本软件不提供任何保证,不承担任何法律责任。 5. 用户使用本软件下载的任何资料,如果侵犯了第三方的知识产权或其他权利,责任由资源发布者或转载者本人承担,本软件对此不承担责任。 6. 用户明确并同意其使用本软件的服务所存在的风险将完全由其本人承担;因其使用本软件服务而产生的一切后果也由其本人承担, 本软件对此不承担任何责任 。 7. 本声明未涉及的问题请参见国家有关法律法规,当本声明与国家有关法律法规冲突时,以国家法律法规为准。 8. 本软件相关声明版权及其修改权、更新权和最终解释权均属软件开发者和运营者所有。
Comments: KinhDown网盘增强工具

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 19-Apr-2020 16:43:59
Detected languages:
  • Chinese - PRC
FileVersion: 1.0.0.0
FileDescription: KinhDown网盘增强工具
ProductName: KinhDown网盘增强工具
ProductVersion: 1.0.0.0
CompanyName: KinhUBAQ_Pro
LegalCopyright: 软件免责声明 1. 本软件仅供爱好者技术交流,请勿用于非法用途,如产生法律纠纷与开发者营运者无关。 2. 一切用户在下载并使用本软件时均被视为已经仔细阅读本声明并完全同意。凡以任何方式登录本软件,使用本软件者,均被视为自愿接受本软件相关声明和用户服务协议的约束。 3. 本软件只提供下载加速功能。 不提供任何下载资源及链接。用户使用本软件下载的内容并不代表本软件之意见及观点,也不代表本软件赞同用户的意图和观点。 4.用户使用本软件加速功能下载的所有资源,其真实性、准确性和合法性由资源发布人和用户本人负责。 本软件不提供任何保证,不承担任何法律责任。 5. 用户使用本软件下载的任何资料,如果侵犯了第三方的知识产权或其他权利,责任由资源发布者或转载者本人承担,本软件对此不承担责任。 6. 用户明确并同意其使用本软件的服务所存在的风险将完全由其本人承担;因其使用本软件服务而产生的一切后果也由其本人承担, 本软件对此不承担任何责任 。 7. 本声明未涉及的问题请参见国家有关法律法规,当本声明与国家有关法律法规冲突时,以国家法律法规为准。 8. 本软件相关声明版权及其修改权、更新权和最终解释权均属软件开发者和运营者所有。
Comments: KinhDown网盘增强工具

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000120

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 19-Apr-2020 16:43:59
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x000D725F
0x000D8000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.53617
.rdata
0x000D9000
0x0003460C
0x00035000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.94588
.data
0x0010E000
0x0006F52A
0x0001F000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.41751
.rsrc
0x0017E000
0x0000BC04
0x0000C000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
6.04434

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.07695
461
Latin 1 / Western European
UNKNOWN
RT_MANIFEST
2
7.70313
5581
Latin 1 / Western European
UNKNOWN
RT_ICON
3
7.91065
11672
Latin 1 / Western European
UNKNOWN
RT_ICON
4
3.71726
296
Latin 1 / Western European
UNKNOWN
RT_ICON
5
3.41337
744
Latin 1 / Western European
UNKNOWN
RT_ICON
6
3.14684
1640
Latin 1 / Western European
UNKNOWN
RT_ICON
7
2.40988
1384
Latin 1 / Western European
UNKNOWN
RT_ICON
8
3.82267
2216
Latin 1 / Western European
UNKNOWN
RT_ICON
9
3.88999
3752
Latin 1 / Western European
UNKNOWN
RT_ICON
10
3.93587
1128
Latin 1 / Western European
UNKNOWN
RT_ICON

Imports

ADVAPI32.dll
AVIFIL32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
MSVFW32.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
WINMM.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start kinhdown网盘增强工具.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3472"C:\Users\admin\AppData\Local\Temp\KinhDown网盘增强工具.exe" C:\Users\admin\AppData\Local\Temp\KinhDown网盘增强工具.exeexplorer.exe
User:
admin
Company:
KinhUBAQ_Pro
Integrity Level:
MEDIUM
Description:
KinhDown网盘增强工具
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\kinhdown网盘增强工具.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvfw32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info