EmbassySecurityCheck.exe

Embassy Security Center

Wave Systems Corp.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘EmbassySecurityCheck’.
Publisher:
Wave Systems Corp.  (signed and verified)

Product:
Embassy Security Center

Description:
ESC Embassy Security Check

Version:
03.10.00.050

MD5:
459f519c68e0b1292486351bd9d5dd3a

SHA-1:
4e3d6bf9bd463ed219a6ceb891295fd0a86efda2

SHA-256:
143c2a0f3f9418c118d28a01192ef27aabd7055f33cbdd6ae4c4d58552f1e5a5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 5:02:32 PM UTC  (today)

File size:
97.3 KB (99,640 bytes)

Product version:
03.10.00.050

Copyright:
©2009 Wave Systems Corp. All rights reserved

Original file name:
EmbassySecurityCheck.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\wave systems corp\embassy security setup\embassysecuritycheck.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/4/2008 7:00:00 AM

Valid to:
11/5/2009 6:59:59 AM

Subject:
CN=Wave Systems Corp., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Wave Systems Corp., L=Lee, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
60E479E6221A9B003570D94686F698C1

File PE Metadata
Compilation timestamp:
6/4/2009 12:04:12 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:EVMYd5FMeIjtqab75b5jFOGZy0aSMgUM8qRMspnttfZzCs7vt6U7x7s2nBH+zsu7:EVdd5FZYtnFjFOGZys7x74

Entry address:
0x9600

Entry point:
48, 83, EC, 28, E8, 87, 03, 00, 00, 48, 83, C4, 28, E9, BE, FC, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, FD, 6E, 00, 00, FF, 15, 97, 1A, 00, 00, 48, 8B, 05, E8, 6F, 00, 00, 48, 89, 44, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, F5, 05, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24, 50, 00, 74, 41, 48, C7, 44, 24, 38, 00, 00, 00, 00, 48, 8D, 44, 24, 48, 48, 89, 44, 24, 30, 48, 8D, 44, 24, 40, 48, 89, 44, 24...
 
[+]

Entropy:
5.6442

Code size:
36.5 KB (37,376 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
EmbassySecurityCheck

Command:
"C:\Program Files\wave systems corp\embassy security setup\embassysecuritycheck.exe"


Scan EmbassySecurityCheck.exe - Powered by Reason Core Security