ActSage.exe

Sage ACT!

Sage Software, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Act! Preloader’.
Publisher:
Sage Software, Inc.  (signed and verified)

Product:
Sage ACT!

Version:
14.1.108.0

MD5:
3d7a20998aa6a704d9701c742205e6f4

SHA-1:
e84d582da02ba279bccd70d9636637152d30d240

SHA-256:
e539027dafb0ab8f09e862f1ff6246d468c99a72be6a0c53e27a814cf1e4fa01

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2018 10:37:36 PM UTC  (today)

File size:
329.3 KB (337,224 bytes)

Product version:
14.1.108.0

Copyright:
Copyright (c) 2009 Sage Software, Inc.

Original file name:
ActSage.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\act\act for windows\actsage.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/17/2009 8:00:00 PM

Valid to:
10/13/2012 7:59:59 PM

Subject:
CN="Sage Software, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Sage Software, Inc.", L=Norcross, S=Georgia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4FE7E174B46F6C2505EB06F0C4243B20

File PE Metadata
Compilation timestamp:
11/16/2011 2:19:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:qhUSfiiw9JuPXgrcwS4k7cDXY6cRHUAg9YdDeEYz:FcgrW4k7cDXx20PhEYz

Entry address:
0x69BE

Entry point:
FF, 25, 00, 20, 00, 11, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.6210

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
20 KB (20,480 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Act! Preloader

Command:
"C:\Program Files\act\act for windows\actsage.exe" -preload