installwow.exe

Blizzard InstallWoW

Blizzard Entertainment, Inc.

This is a setup and installation application. The file has been seen being downloaded from www.wow-europe.com.
Publisher:
Blizzard Entertainment  (signed by Blizzard Entertainment, Inc.)

Product:
Blizzard InstallWoW

Version:
1, 4, 0, 371

MD5:
fd08591d234c44308b6d442b09626e40

SHA-1:
c6fb9a183524845afc73d55a19f9392032c13663

SHA-256:
af4778edd3146c27965807aeb2838556941aa0aae032b2b272617643576a69e9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 7:21:35 PM UTC  (today)

File size:
1.6 MB (1,663,664 bytes)

Product version:
1, 4, 0, 371

Copyright:
(c) 2007-2008 Blizzard Entertainment Inc.

Original file name:
TryWoW.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
1/8/2010 2:00:00 AM

Valid to:
12/6/2011 1:59:59 AM

Subject:
CN="Blizzard Entertainment, Inc.", OU=TECHNICAL SUPPORT, O="Blizzard Entertainment, Inc.", L=Irvine, S=California, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
7B715B3347BC57B25C66B34202F4A1A0

File PE Metadata
Compilation timestamp:
2/2/2010 7:37:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:QYxmgLau8NyLJSIwl2GkBRzUAhsMjQzRJWMuTyOW6CI3aW53yoodf:QYMLNMJUl23RzXsMjQVgMuT7W6CwRwf

Entry address:
0x885FB

Entry point:
E8, 1C, AF, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 8B, 7D, 08, 33, C0, 83, C9, FF, F2, AE, 83, C1, 01, F7, D9, 83, EF, 01, 8A, 45, 0C, FD, F2, AE, 83, C7, 01, 38, 07, 74, 04, 33, C0, EB, 02, 8B, C7, FC, 5F, C9, C3, CC, CC, CC, 80, F9, 40, 73, 15, 80, F9, 20, 73, 06, 0F, AD, D0, D3, EA, C3, 8B, C2, 33, D2, 80, E1, 1F, D3, E8, C3, 33, C0, 33, D2, C3, 6A, 10, 68, 38, C1, 4E, 00, E8, 39, 23, 00, 00, 33, C0, 33, DB, 39, 5D, 08, 0F, 95, C0, 3B, C3, 75, 20, E8, F4...
 
[+]

Code size:
644 KB (659,456 bytes)

The file installwow.exe has been seen being distributed by the following URL.

Scan installwow.exe - Powered by Reason Core Security