howling teamspeak-overwolfinstaller.exe

Overwolf Installer

Overwolf Ltd

Publisher:
Overwolf  (signed by Overwolf Ltd)

Product:
Overwolf Installer

Version:
1.41.0.0

MD5:
6cfee41320dc765fc1506869be519c6b

SHA-1:
e7dc44ec4814366cc5bddde41fccdc0c74c14099

SHA-256:
12e0eb8437b34f367019b45a69d7ed759d02e12c7d58369ea8043cab0057cde2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 5:41:27 AM UTC  (today)

File size:
1.6 MB (1,704,224 bytes)

Product version:
1.41.0.0

Copyright:
Copyright © Overwolf 2015

Original file name:
OWInstaller.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\howling teamspeak-overwolfinstaller.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/22/2014 7:00:00 PM

Valid to:
2/21/2017 6:59:59 PM

Subject:
CN=Overwolf Ltd, O=Overwolf Ltd, L=Tel-Aviv, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1249C91E5611F73BD94274B6C30DDE54

File PE Metadata
Compilation timestamp:
8/11/2015 9:31:24 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:rM8d/ucxs8reVfk8KlRi583WKd3IkVYL2rVvCx7ZVqGoI9f:Sms8reVfJKlQ5IWwIkVYL2RqZ3oO

Entry address:
0x19965E

Entry point:
FF, 25, 6C, 96, 59, 00, 00, 00, 00, 00, 00, 00, 00, 00, 40, 96, 19, 00, 00, 00, 00, 00, 00, 00, 00, 00, 2C, F9, C9, 55, 00, 00, 00, 00, 02, 00, 00, 00, 6E, 00, 00, 00, 90, 96, 19, 00, 90, 78, 19, 00, 52, 53, 44, 53, 4E, 85, 51, A1, 1A, 87, 82, 48, B9, EA, 43, 26, B7, F8, 36, 21, 01, 00, 00, 00, 43, 3A, 5C, 4F, 76, 65, 72, 77, 6F, 6C, 66, 5C, 49, 6E, 44, 65, 76, 5C, 4D, 61, 69, 6E, 44, 65, 76, 5C, 53, 6F, 75, 72, 63, 65, 5C, 4F, 57, 49, 6E, 73, 74, 61, 6C, 6C, 65, 72, 5C, 4F, 57, 49, 6E, 73, 74, 61, 6C, 6C...
 
[+]

Entropy:
6.2928

Code size:
1.6 MB (1,669,120 bytes)

The file howling teamspeak-overwolfinstaller.exe has been seen being distributed by the following URL.

Scan howling teamspeak-overwolfinstaller.exe - Powered by Reason Core Security