divxvodplayer.exe

DivX Setup

DivX, LLC

Publisher:
DivX, LLC  (signed and verified)

Product:
DivX Setup

Version:
2.7.1.2

MD5:
aa9a0099f2e3eb57770f7b0ee8fad53e

SHA-1:
2573597633fa2408eb1b2140d2d6fe9f0a1b800e

SHA-256:
ba17efb87699b1a8c1f8d2c9f8c57edd8203242390f5f47c73d4fe36980bb2d1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 8:28:03 PM UTC  (today)

File size:
990 KB (1,013,744 bytes)

Product version:
2.7.1.2

Copyright:
2015 DivX, LLC.

Original file name:
DivXSetup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\divxvodplayer.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
12/15/2014 8:00:00 AM

Valid to:
1/15/2016 7:59:59 AM

Subject:
CN="DivX, LLC", O="DivX, LLC", L=San Diego, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
2A2A440139AEA302DF5362C6CA56C6E5

File PE Metadata
Compilation timestamp:
10/1/2015 3:06:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:muEe+twRRhVq/2BoPQ1ekl21oG3jMPMeqZdLVISK:mww2Bq/2YQ1XLGIP5EdLVISK

Entry address:
0x87F10

Entry point:
E8, AA, EB, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, 7A, 7F, 48, 00, 6A, 00, FF, 75, 0C, FF, 75, F8, FF, 75, 08, E8, A4, 92, 01, 00, 8B, 45, 0C, 8B, 40, 04, 83, E0, FD, 8B, 4D, 0C, 89, 41, 04, 64, 8B, 3D, 00, 00, 00, 00...
 
[+]

Entropy:
6.4164

Code size:
700.5 KB (717,312 bytes)

The file divxvodplayer.exe has been seen being distributed by the following 2 URLs.

http://download.divx.com/.../DivXVODPlayer.exe

Scan divxvodplayer.exe - Powered by Reason Core Security