memopal.exe

Memopal Srl

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Memopal’.
Publisher:
Memopal Srl  (signed and verified)

MD5:
44adbe2c818532199c8265197a937662

SHA-1:
05c2c09ae1063b48a4690f588d276081750867df

SHA-256:
58d1b8c772d63556d6a67cbd1078b9b79a52a606485f236d29070af42d8eae72

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 8:59:29 PM UTC  (today)

File size:
1.9 MB (1,994,744 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\memopal\memopal.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
12/20/2012 3:08:25 PM

Valid to:
12/20/2014 3:08:25 PM

Subject:
CN=Memopal Srl, O=Memopal Srl, L=Roma, S=RM, C=IT

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
04692F6DBD5A67

File PE Metadata
Compilation timestamp:
10/28/2014 5:10:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:rcvhQGcr79KsAigIeFhGp7he6bqxB5f1tAZG5lwPkBn3OM1p/howMOBawDr6iYk:rcZCtKnF27jbej1WA5661p/ho4r6iYk

Entry address:
0x52DB2

Entry point:
E8, 11, 04, 00, 00, E9, 37, FD, FF, FF, FF, 25, F0, F3, 51, 00, FF, 25, F8, F3, 51, 00, FF, 25, FC, F3, 51, 00, FF, 25, 0C, F4, 51, 00, FF, 25, 10, F4, 51, 00, FF, 25, 14, F4, 51, 00, FF, 25, 18, F4, 51, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 50, 38, 58, 00, 89, 0D, 4C, 38, 58, 00, 89, 15, 48, 38, 58, 00, 89, 1D, 44, 38, 58, 00, 89, 35, 40, 38, 58, 00, 89, 3D, 3C, 38, 58, 00, 66, 8C, 15, 68, 38, 58, 00, 66, 8C, 0D, 5C, 38, 58, 00, 66, 8C, 1D, 38, 38, 58, 00, 66, 8C, 05, 34, 38, 58, 00, 66, 8C...
 
[+]

Code size:
1.1 MB (1,171,456 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Memopal

Command:
"C:\Program Files\memopal\memopal.exe" \delayed


Scan memopal.exe - Powered by Reason Core Security