core.exe

GAS Tecnologia - Protection

GAS INFORMATICA LTDA

It runs as a separate (within the context of its own process) windows Service named “Warsaw Technology”.
Publisher:
GAS Tecnologia LTDA  (signed by GAS INFORMATICA LTDA)

Product:
GAS Tecnologia - Protection

Description:
GAS Tecnologia - Core

Version:
2.7.3.6028

MD5:
8e6b57397120d335c2ca860b347f200a

SHA-1:
48e44632e672796bb8d4e21b953968c1f53f6c38

SHA-256:
6a93330c124b2542514d736bdda62524b5860d1c9a87ad6329bb9dcbd1c1162e

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 12:37:20 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.CFI.Gen
7.11.30.172

File size:
825.3 KB (845,112 bytes)

Product version:
2.7.3.6028

Copyright:
Copyright © 2014 - GAS Tecnologia

File type:
Executable application (Win64 EXE)

Language:
Brazilian Portuguese

Common path:
C:\Program Files\diebold\warsaw\core.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/30/2012 9:00:00 PM

Valid to:
8/13/2015 8:59:59 PM

Subject:
CN=GAS INFORMATICA LTDA, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=GAS INFORMATICA LTDA, L=Brasilia, S=Distrito Federal, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
58C005F9811C3FD333668072A04E0D1B

File PE Metadata
Compilation timestamp:
8/4/2014 8:50:27 AM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:SGcbtPLgv+TvVlL1xgVdSjF3g55Au13YlX8Y24q31JF:ob3bwS3uWBVq31T

Entry address:
0xAF59F

Entry point:
E9, D8, 59, 00, 00, 0F, 87, B6, D9, FF, FF, 0F, A3, C0, F9, F8, E9, C6, 47, 00, 00, 00, 00, 77, 63, 73, 63, 61, 74, 5F, 73, 00, F8, F5, F9, 69, D2, 0A, 00, 00, 00, E9, A8, 70, 00, 00, 00, 00, 45, 6E, 63, 6F, 64, 65, 50, 6F, 69, 6E, 74, 65, 72, 00, 00, 00, 5F, 5F, 73, 65, 74, 75, 73, 65, 72, 6D, 61, 74, 68, 65, 72, 72, 00, F2, AE, E9, 24, 75, 00, 00, 0F, 85, 63, D9, FF, FF, F5, C6, 47, FF, 00, F9, F9, 66, 0F, BA, E2, 01, 48, F7, C4, 08, 00, 00, 00, E9, 5F, 68, 00, 00, B7, 32, 25, BD, 96, D9, 53, 42, 8A, 91...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
438 KB (448,512 bytes)

Service
Display name:
Warsaw Technology

Type:
Win32OwnProcess


Scan core.exe - Powered by Reason Core Security