MetascanClient.exe

Metascan Client

OPSWAT, Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from software.opswat.com and multiple other hosts.
Publisher:
OPSWAT, Inc.  (signed and verified)

Product:
Metascan Client

Version:
3, 0, 3, 20958

MD5:
672ed66c134bc7b7d87677e5829ae66f

SHA-1:
14ce3604e8c6a7ba57c4a81a4654c1df1de8a560

SHA-256:
c9b55dc00c2b3f7179c9d51f93c3cb4a4160864ab449abe005effcd20430d5b1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:10:29 PM UTC  (today)

File size:
3.2 MB (3,373,376 bytes)

Product version:
3, 0, 3, 20958

Copyright:
Copyright (C) OPSWAT, Inc. All rights reserved.

Original file name:
MetascanClient.exe

File type:
Executable application (Win64 EXE)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/8/2012 3:00:00 AM

Valid to:
8/9/2015 2:59:59 AM

Subject:
CN="OPSWAT, Inc.", OU=Engineering, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="OPSWAT, Inc.", L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A357339C3B74C1FE1DEB8981CF0278D

File PE Metadata
Compilation timestamp:
10/25/2013 1:39:58 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:lWfjxbelMfgeO1MV8J/MZQ7Wz/MTA7dO4NPLMC0jBcxRa0yfMqUwbuC9VHW3MyVh:kOMjmMV8J2Q79Fcx9oUwbpHW9

Entry address:
0x1A2780

Entry point:
48, 83, EC, 28, E8, 0B, AC, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, C9, F6, 0F, 00, 75, 11, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 02, F3, C3, 48, C1, C9, 10, E9, 79, AC, 00, 00, CC, EB, 09, 66, 3B, C2, 74, 11, 48, 83, C1, 02, 0F, B7, 01, 66, 85, C0, 75, EF, 66, 3B, C2, 75, 04, 48, 8B, C1, C3, 33, C0, C3, CC, 48, 89, 5C, 24, 10, 48, 89, 6C, 24, 18, 48, 89, 74, 24, 20, 57...
 
[+]

Code size:
1.9 MB (2,022,912 bytes)

The file MetascanClient.exe has been seen being distributed by the following 3 URLs.

Scan MetascanClient.exe - Powered by Reason Core Security