memopal.exe

Memopal Srl

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Memopal’.
Publisher:
Memopal Srl  (signed and verified)

MD5:
dba4ac3a3802c78774585e37055dc586

SHA-1:
6cf97e16c5efcd5715b15b7a7234be6f48818835

SHA-256:
74d1d0116591d3e5efcd8b5a391a5cddb41a4321eea74dcd4df927d31e5d39d0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 10:35:32 PM UTC  (today)

File size:
1.9 MB (1,995,256 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\memopal\memopal.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
12/20/2012 1:08:25 PM

Valid to:
12/20/2014 1:08:25 PM

Subject:
CN=Memopal Srl, O=Memopal Srl, L=Roma, S=RM, C=IT

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
04692F6DBD5A67

File PE Metadata
Compilation timestamp:
12/4/2014 1:49:08 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:3ygXOd+ttWAxJs0hJQhdGNtWwp/P+Sk0MCoD:UdgQKicNt1Y

Entry address:
0x52ECC

Entry point:
E8, 07, 04, 00, 00, E9, 37, FD, FF, FF, FF, 25, F0, 03, 52, 00, FF, 25, F8, 03, 52, 00, FF, 25, FC, 03, 52, 00, FF, 25, 0C, 04, 52, 00, FF, 25, 10, 04, 52, 00, FF, 25, 14, 04, 52, 00, FF, 25, 18, 04, 52, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 80, 48, 58, 00, 89, 0D, 7C, 48, 58, 00, 89, 15, 78, 48, 58, 00, 89, 1D, 74, 48, 58, 00, 89, 35, 70, 48, 58, 00, 89, 3D, 6C, 48, 58, 00, 66, 8C, 15, 98, 48, 58, 00, 66, 8C, 0D, 8C, 48, 58, 00, 66, 8C, 1D, 68, 48, 58, 00, 66, 8C, 05, 64, 48, 58, 00, 66, 8C...
 
[+]

Code size:
1.1 MB (1,171,968 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Memopal

Command:
"C:\Program Files\memopal\memopal.exe" \delayed


Scan memopal.exe - Powered by Reason Core Security