| File name: | C:\Windows\SysWOW64\Macromed\Flash\FlashHelperService.exe | 
| Full analysis: | https://app.any.run/tasks/6c8af0e4-97ce-4a23-ab57-051c678ba61c | 
| Verdict: | No threats detected | 
| Analysis date: | April 08, 2020, 02:58:17 | 
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) | 
| Indicators: | |
| MIME: | application/x-dosexec | 
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows | 
| MD5: | 5D34464531DDBDC7B0A4DBA5B4C1CFEA | 
| SHA1: | 465EFC26493BBAD3EFC11A2929CDE4928E122C03 | 
| SHA256: | A545DF34334B39522B9CC8CC0C11A1591E016539B209CA1D4AB8626D70A54776 | 
| SSDEEP: | 49152:vffp8HGzfudlNe2dcEZfkGisGapVCnxnlxS5OckUnp/x5krWx0Z:B8ldlLzfkGisGaqnxnbA | 
| .exe | | | Win64 Executable (generic) (76.4) | 
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) | 
| .exe | | | Generic Win/DOS Executable (5.5) | 
| .exe | | | DOS Executable Generic (5.5) | 
| MachineType: | Intel 386 or later, and compatibles | 
|---|---|
| TimeStamp: | 2020:02:12 04:13:44+01:00 | 
| PEType: | PE32 | 
| LinkerVersion: | 12 | 
| CodeSize: | 1985536 | 
| InitializedDataSize: | 770048 | 
| UninitializedDataSize: | - | 
| EntryPoint: | 0x19f385 | 
| OSVersion: | 5.1 | 
| ImageVersion: | - | 
| SubsystemVersion: | 5.1 | 
| Subsystem: | Windows GUI | 
| FileVersionNumber: | 2.1.0.32 | 
| ProductVersionNumber: | 2.1.0.32 | 
| FileFlagsMask: | 0x003f | 
| FileFlags: | (none) | 
| FileOS: | Windows NT 32-bit | 
| ObjectFileType: | Executable application | 
| FileSubtype: | - | 
| LanguageCode: | Chinese (Simplified) | 
| CharacterSet: | Unicode | 
| CompanyName: | 重庆重橙网络科技有限公司 | 
| FileDescription: | Flash Helper Service | 
| FileVersion: | 2.1.0.32 | 
| InternalName: | FlashHelperServices.exe | 
| LegalCopyright: | Copyright(C) 2019 重庆重橙网络科技有限公司.All Rights Reserved | 
| OriginalFileName: | FlashHelperService.exe | 
| ProductName: | Flash Helper Service | 
| ProductVersion: | 2.1.0.32 | 
| Architecture: | IMAGE_FILE_MACHINE_I386 | 
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI | 
| Compilation Date: | 12-Feb-2020 03:13:44 | 
| Detected languages: | 
 | 
| Debug artifacts: | 
 | 
| CompanyName: | 重庆重橙网络科技有限公司 | 
| FileDescription: | Flash Helper Service | 
| FileVersion: | 2.1.0.32 | 
| InternalName: | FlashHelperServices.exe | 
| LegalCopyright: | Copyright(C) 2019 重庆重橙网络科技有限公司.All Rights Reserved | 
| OriginalFilename: | FlashHelperService.exe | 
| ProductName: | Flash Helper Service | 
| ProductVersion: | 2.1.0.32 | 
| Magic number: | MZ | 
|---|---|
| Bytes on last page of file: | 0x0090 | 
| Pages in file: | 0x0003 | 
| Relocations: | 0x0000 | 
| Size of header: | 0x0004 | 
| Min extra paragraphs: | 0x0000 | 
| Max extra paragraphs: | 0xFFFF | 
| Initial SS value: | 0x0000 | 
| Initial SP value: | 0x00B8 | 
| Checksum: | 0x0000 | 
| Initial IP value: | 0x0000 | 
| Initial CS value: | 0x0000 | 
| Overlay number: | 0x0000 | 
| OEM identifier: | 0x0000 | 
| OEM information: | 0x0000 | 
| Address of NE header: | 0x00000138 | 
| Signature: | PE | 
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 | 
| Number of sections: | 6 | 
| Time date stamp: | 12-Feb-2020 03:13:44 | 
| Pointer to Symbol Table: | 0x00000000 | 
| Number of symbols: | 0 | 
| Size of Optional Header: | 0x00E0 | 
| Characteristics: | 
 | 
| Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy | 
|---|---|---|---|---|---|
| .text | 0x00001000 | 0x001E4A6C | 0x001E4C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.6101 | 
| .rdata | 0x001E6000 | 0x0006E7C2 | 0x0006E800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.4102 | 
| .data | 0x00255000 | 0x00011F08 | 0x0000D200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.33348 | 
| Shared | 0x00267000 | 0x00000004 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_WRITE | 0 | 
| .rsrc | 0x00268000 | 0x00024F30 | 0x00025000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.11824 | 
| .reloc | 0x0028D000 | 0x00016478 | 0x00016600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.60303 | 
| Title | Entropy | Size | Codepage | Language | Type | 
|---|---|---|---|---|---|
| 1 | 5.3298 | 822 | UNKNOWN | English - United States | RT_MANIFEST | 
| 2 | 3.12559 | 16936 | UNKNOWN | Chinese - PRC | RT_ICON | 
| 3 | 3.13154 | 9640 | UNKNOWN | Chinese - PRC | RT_ICON | 
| 4 | 3.40023 | 6760 | UNKNOWN | Chinese - PRC | RT_ICON | 
| 5 | 3.21799 | 4264 | UNKNOWN | Chinese - PRC | RT_ICON | 
| 6 | 3.48788 | 2440 | UNKNOWN | Chinese - PRC | RT_ICON | 
| 7 | 1.95751 | 72 | UNKNOWN | Chinese - PRC | RT_STRING | 
| 8 | 3.44435 | 1128 | UNKNOWN | Chinese - PRC | RT_ICON | 
| 9 | 4.36861 | 9640 | UNKNOWN | Chinese - PRC | RT_ICON | 
| 10 | 4.69256 | 4264 | UNKNOWN | Chinese - PRC | RT_ICON | 
| ADVAPI32.dll | 
| COMCTL32.dll | 
| CRYPT32.dll | 
| GDI32.dll | 
| IPHLPAPI.DLL | 
| KERNEL32.dll | 
| OLEAUT32.dll | 
| PSAPI.DLL | 
| SHELL32.dll | 
| SHLWAPI.dll | 
| PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2940 | "C:\Users\admin\AppData\Local\Temp\FlashHelperService.exe" | C:\Users\admin\AppData\Local\Temp\FlashHelperService.exe | — | explorer.exe | |||||||||||
| User: admin Company: 重庆重橙网络科技有限公司 Integrity Level: MEDIUM Description: Flash Helper Service Exit code: 2 Version: 2.1.0.32 Modules
 | |||||||||||||||