netsession_win.exe

Akamai NetSession Client

GeoTrust Inc.

Publisher:
Akamai Technologies, Inc.  (signed by GeoTrust Inc.)

Product:
Akamai NetSession Client

Version:
1.9.3.1

MD5:
d16d21a81efd458c5ddf5e24affe338b

SHA-1:
7f15f6f80dd0c95da88877d5eadc65d41e8b9c1f

Scanner detections:
23 / 68

Status:
Clean  (23 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/19/2024 9:34:40 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Win32.Neshta.B
7.1.1

AhnLab V3 Security
Win32/ChiHack.6652
2015.07.13

Avira AntiVirus
W32/Neshta.A
3.6.1.96

avast!
Win32:SaliCode
2014.9-160210

AVG
Win32/Neshta.A
2017.0.2837

Bkav FE
W32.HfsAutoB
1.3.0.4959

Clam AntiVirus
WIN.Worm.Brontok
0.98/21511

Comodo Security
EmailWorm.Win32.Runonce.~v001
22748

Dr.Web
Win32.Runonce.6652
9.0.1.041

F-Prot
W32/Thecid.B@mm
v6.4.6.5.141

IKARUS anti.virus
Email-Worm.Win32.Runouce
t3scan.1.9.5.0

K7 AntiVirus
EmailWorm
13.205.16534

Microsoft Security Essentials
Threat.Undefined
1.201.1583.0

NANO AntiVirus
Trojan.Win32.IframeExec.dteiuc
0.30.24.2487

Norman
Sality.ZHB
11.20160210

Panda Antivirus
Generic Malware
16.02.10.04

Quick Heal
W32.Runouce.B
2.16.14.00

Rising Antivirus
PE:Worm.ChineseHacker-2!23772
23.00.65.16208

Trend Micro House Call
PE_SALITY.RL
7.2.41

Trend Micro
PE_SALITY.RL
10.465.10

Vba32 AntiVirus
Virus.Win32.Chur.A
3.12.26.4

VIPRE Antivirus
Threat.219451
40786

Zillya! Antivirus
Worm.RunOnce.Win32.2
2.0.0.2283

File size:
4.5 MB (4,769,208 bytes)

Product version:
1.9.3.1

Copyright:
Copyright (C) 2007 - 2015 Akamai Technologies, Inc.

Original file name:
netsession_win.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Application data\akamai\netsession_win.exe

Digital Signature
Signed by:

Authority:
GeoTrust Inc.

Valid from:
5/21/2002 6:00:00 AM

Valid to:
5/21/2022 6:00:00 AM

Subject:
CN=GeoTrust Global CA, O=GeoTrust Inc., C=US

Issuer:
CN=GeoTrust Global CA, O=GeoTrust Inc., C=US

Serial number:
023456

File PE Metadata
Compilation timestamp:
9/10/2015 9:58:17 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:ulP4JhY4YqIEsuctQViU/hFHodN78ZN+M/OPgXVwe2u+6+Rg9:ulq6yctjUAdNomM/OPgXVsw

Entry address:
0x187C1A

Entry point:
60, 23, D6, 81, F6, 31, B3, 5C, E1, 69, CF, 8A, 45, 46, 27, FF, CF, B7, 90, 0F, B7, D0, F2, 89, DF, 52, 55, 77, 02, 87, D3, EB, 04, 33, ED, 13, C6, 1A, D5, 84, DC, 68, 01, 10, 00, 00, 3B, C1, 71, 05, 85, C9, 0F, B6, CD, 5E, 74, 0A, 81, E8, AA, 90, 57, 83, 88, F2, 88, E6, 81, EE, 1B, 0B, 00, 00, 4E, 0F, AF, FA, 2A, E0, 8D, 2D, BE, 15, 3E, 34, 09, C8, 86, DA, 80, FB, 0D, 1A, C7, 81, FE, AE, 00, 00, 00, 0F, 85, DF, FF, FF, FF, 0F, BF, DF, 4D, 4D, C7, C7, 2A, BD, A3, B4, E8, 08, 00, 00, 00, F3, 76, 02, 22, D6...
 
[+]

Entropy:
6.8821

Code size:
2.9 MB (3,040,768 bytes)

Windows Firewall Allowed Program
Name:
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Akamai\netsession_win.exe


Scan netsession_win.exe - Powered by Reason Core Security