0cd5d2d8b52c4dcd3e1807ed83562e9b138653f1

Canonical, Ltd

It is installed within the Mozilla Firefox web browser as part of an addin/plugin.
Publisher:
Canonical, Ltd  (signed and verified)

MD5:
475340128ef9d0dd00a766ff469d656a

SHA-1:
eca85c0a98122a26a8ab8f4a1b65d67bd75cd9b1

SHA-256:
0e0ff553a0a6cced47698effd7a706ff038553ac96cd9aa0b0d2a5a99f408ab1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 8:57:37 PM UTC  (today)

File size:
1.5 MB (1,539,641 bytes)

Common path:
C:\users\{user}\appdata\local\mozilla\firefox\profiles\{user}.default\cache2\entries\0cd5d2d8b52c4dcd3e1807ed83562e9b138653f1

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
4/19/2009 8:00:00 PM

Valid to:
4/20/2010 7:59:59 PM

Subject:
CN="Canonical, Ltd", O="Canonical, Ltd", L=Douglas, S=N/A, C=IM

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
7A88B237F0A864E8E53E09D05E17BA78

File PE Metadata
Compilation timestamp:
4/21/2009 4:41:50 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
24576:Xl7uCEvPzzExj4sWV8/aLeDDAZQoZ7KIrDTv27gs7ffCJfb5ZHaK6+cpGsTIuqjy:Xliy4Bi9gZj77Tv271jCFH63tpGsgFE5

Entry address:
0x1240

Entry point:
55, 89, E5, 83, EC, 14, 6A, 02, FF, 15, EC, 91, 40, 00, E8, BD, FE, FF, FF, 8D, B6, 00, 00, 00, 00, 8D, BC, 27, 00, 00, 00, 00, 55, 8B, 0D, 00, 92, 40, 00, 89, E5, 5D, FF, E1, 8D, 74, 26, 00, 55, 8B, 0D, F8, 91, 40, 00, 89, E5, 5D, FF, E1, 90, 90, 90, 90, 55, 89, E5, 83, EC, 08, A1, 40, 60, 40, 00, 85, C0, 74, 3B, 83, EC, 0C, 68, 00, 70, 40, 00, E8, A0, 46, 00, 00, 89, C2, 83, C4, 0C, B8, 00, 00, 00, 00, 85, D2, 74, 0F, 50, 50, 68, 0D, 70, 40, 00, 52, E8, 95, 46, 00, 00, 5A, 59, 85, C0, 74, 0D, 83, EC, 0C...
 
[+]

Entropy:
7.9911

Packer / compiler:
Dev-C++ v5

Code size:
19 KB (19,456 bytes)

Scan 0cd5d2d8b52c4dcd3e1807ed83562e9b138653f1 - Powered by Reason Core Security