ehshell.exe

The MediaMall

MediaMall Technologies, Inc.

Publisher:
MediaMall Technologies, Inc.  (signed and verified)

Product:
The MediaMall

Description:
MediaMall

Version:
2.57.3034.40742

MD5:
48287a8b2ec4e469053a5136c289e9fb

SHA-1:
4ac9903c7cd159fb2946c9457eefa25019026963

SHA-256:
f43c2e0cce5474def6d194e93cb0d4cfbde1230873d05d3499650505ec933af5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/3/2024 5:15:54 AM UTC  (today)

File size:
2 MB (2,148,304 bytes)

Product version:
2.57.3034.40742

Copyright:
© 2003-2008 MediaMall Technologies, Inc. All rights reserved.

Original file name:
ehshell.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\mediamall\ehshell.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
8/14/2007 8:00:00 PM

Valid to:
11/11/2009 6:59:59 PM

Subject:
CN="MediaMall Technologies, Inc.", OU=SECURE APPLICATION DEVELOPMENT, O="MediaMall Technologies, Inc.", L=New York, S=New York, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
2C5DFBC6EE9B824C497524E9BF6F1B0B

File PE Metadata
Compilation timestamp:
4/22/2008 6:38:34 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:yRzyuBQyxedgbPjQkN7EUYz33QgV8N+7hLE5ODy88IKejsSA4Jswf2xCdOgEQoMn:yRzBQxydtuHQgV8N+7hLE5OfVJGQog

Entry address:
0x205C62

Entry point:
FF, 25, 70, 5C, 60, 00, 00, 00, 00, 00, 00, 00, 00, 00, 44, 5C, 20, 00, 00, 00, 00, 00, 00, 00, 00, 00, EA, 68, 0E, 48, 00, 00, 00, 00, 02, 00, 00, 00, 86, 00, 00, 00, 94, 5C, 20, 00, 94, 40, 20, 00, 52, 53, 44, 53, D0, 78, F6, 22, 92, B6, 76, 4B, 98, 30, BC, 6F, 7C, EA, A7, 51, 01, 00, 00, 00, 43, 3A, 5C, 44, 6F, 63, 75, 6D, 65, 6E, 74, 73, 20, 61, 6E, 64, 20, 53, 65, 74, 74, 69, 6E, 67, 73, 5C, 44, 61, 76, 69, 64, 20, 4B, 61, 72, 6C, 74, 6F, 6E, 5C, 4D, 79, 20, 44, 6F, 63, 75, 6D, 65, 6E, 74, 73, 5C, 56...
 
[+]

Entropy:
6.3065

Code size:
2 MB (2,113,024 bytes)

Scan ehshell.exe - Powered by Reason Core Security