Escolar.exe

Longman Dicionario Escolar

Lingea s.r.o.

This is a setup program which is used to install the application. The file has been seen being downloaded from doc-0g-10-docs.googleusercontent.com and multiple other hosts.
Publisher:
Pearson Education  (signed by Lingea s.r.o.)

Product:
Longman Dicionario Escolar

Version:
2, 0, 0, 0

MD5:
f986c15db05d46214ca797eb07da0f4f

SHA-1:
65172805e04af958e36802b6c597f94fec0ce18f

SHA-256:
2cc54b70fb07bbf3fd3561938c799606b6ebbebb5090742132908f039749bf9d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/18/2017 5:00:18 PM UTC  (today)

File size:
2 MB (2,110,744 bytes)

Product version:
2, 0, 0, 0

Copyright:
(c) Pearson Education 2012. All rights reserved.

Original file name:
Escolar.exe

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\Program Files\longman\longman escolar 2\escolar.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/19/2009 9:00:00 PM

Valid to:
4/27/2012 8:59:59 PM

Subject:
CN=Lingea s.r.o., OU=Language Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lingea s.r.o., L=Brno, S=www.lingea.com, C=CZ

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
60201F9DBA128BC02EB0A82438C7FF8D

File PE Metadata
Compilation timestamp:
3/28/2012 2:18:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:VSmbLhNenREIX9hvlpZwUuJKjF7ByJV2l2uowp1N7rV56s8fmBRXFg:xsEIrHluMjGJV2l2Dy1NPV8srBA

Entry address:
0x1763CC

Entry point:
E8, 48, CF, 00, 00, E9, 16, FE, FF, FF, 6A, 00, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, FF, 74, 24, 14, E8, C0, CF, 00, 00, 83, C4, 14, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, F0, 45, 5F, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, F0, 45, 5F, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC...
 
[+]

Code size:
1.6 MB (1,679,360 bytes)

The file Escolar.exe has been seen being distributed by the following 2 URLs.

https://doc-0g-10-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/8s7ag8dhmsaa61dp8tm2o2jce75djqb9/1479340800000/11367942142977405749/.../0B3tUwrFvAT_XbW9GMEl5RFFsZGc?e=download

temp:Escolar.exe

Scan Escolar.exe - Powered by Reason Core Security