38177828

File Helper

GitHub, Inc

Publisher:
File Helpers  (signed by GitHub, Inc)

Product:
File Helper

Version:
5.8.0.0

MD5:
5342c5d77a3e24d5259c17f1cedb2cfd

SHA-1:
d7c8d10d790f15c6cfe63f66fae9084243bc690a

SHA-256:
f4ed598bd57c8c312ec832732ded05885c5aba83ed827aeb0b0776697e6c1db6

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/26/2024 9:41:09 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/TrojanDownloader.Small.AEO trojan
7.0.302.0

File size:
187.6 KB (192,096 bytes)

Product version:
5.8.0.0

Copyright:
Copyright © 2013

Trademarks:
File Helpers

Original file name:
HmmCrytd.exe

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\virtualstore\Program Files\lan monitor\38177828

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/7/2013 7:00:00 PM

Valid to:
6/6/2016 7:59:59 PM

Subject:
CN="GitHub, Inc", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="GitHub, Inc", L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2EA078CF4DAE81459313B225E26B568B

File PE Metadata
Compilation timestamp:
1/1/2016 9:02:23 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:O49VfGEpFOTLlDgXN7mBAeSDurYd2s82vyyI2NsWrP6GcTfM0A3Cdvlq3MOQuPym:J7dbOlDcsBAh6rY9q9POaqy3jiGQbm92

Entry address:
0x325E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
8 KB (8,192 bytes)

Scan 38177828 - Powered by Reason Core Security