inFlowInstaller.exe

inFlow Inventory

Archon Systems Inc.

This is a self-extracting archive and installer.
Publisher:
Archon Systems Inc.  (signed and verified)

Product:
inFlow Inventory

Version:
2.5.0

MD5:
2567ab9634aa325f5150ac541fda9022

SHA-1:
4183bc2bcf1d9ae60fdebd4075fb99e18ff92e12

SHA-256:
b6979f7b9b0ec771db36e3070d3e4b12d7621eef9880054bb50fcf28fbf659fa

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2016 6:13:50 AM UTC  (eleven months)

File size:
699 KB (715,816 bytes)

Product version:
2.5.0

Copyright:
Copyright (c) Archon Systems Inc.. All rights reserved.

Original file name:
inFlowInstaller.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\.be\inflowinstaller.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/20/2011 8:00:00 AM

Valid to:
9/20/2016 7:59:59 AM

Subject:
CN=Archon Systems Inc., O=Archon Systems Inc., STREET=1207-4725 Sheppard Ave E., L=Toronto, S=Ontario, PostalCode=M1S 5B2, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B42697BFC8ED46033F50285947521FEE

File PE Metadata
Compilation timestamp:
9/3/2012 9:44:40 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:0Kbe2meV3IipMkHmCoj86wTBsLviCLACNiVCxD52yxHyhnnRopTuIAXY:6lE3FHmfgJsLvrLAyESZSJCpTuIaY

Entry address:
0x474B

Entry point:
E8, AC, 14, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 2A, 83, 78, 10, 03, 75, 24, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 05, E8, 01, 15, 00, 00, 33, C0, 5D, C2, 04, 00, 68, 55, 47, 40, 00, FF, 15, 7C, 11, 40, 00, 33, C0, C3, 8B, FF, 55, 8B, EC, 57, BF, E8, 03, 00, 00, 57, FF, 15, 84, 11, 40, 00, FF, 75, 08, FF, 15, 80, 11, 40, 00, 81, C7, E8, 03, 00, 00, 81, FF, 60, EA, 00...
 
[+]

Entropy:
7.4240

Code size:
311.5 KB (318,976 bytes)

Startup File (All Users Run Once)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Name:
{5498e887-d9b5-4ed8-93aa-48ad28d9827e}

Command:
"C:\ProgramData\package cache\{5498e887-d9b5-4ed8-93aa-48ad28d9827e}\inflowinstaller.exe" \burn.log.append "C:\users\{user}\appdata\local\temp\{random}.tmp\burn.runonce


Scan inFlowInstaller.exe - Powered by Reason Core Security