openvpnas.exe

AnchorFree Inc

It runs as a windows Service named “Hotspot Shield Service”.
Publisher:
AnchorFree Inc  (signed and verified)

MD5:
bc3e3d32b67cb46d906d7c48916aacc8

SHA-1:
fcf56b410b7a5fbdf55bd2d4c6140e983a2dffbc

SHA-256:
87c317df74205ab73d39b0df4b3c01f50c33ae68574480998614e81a816aac64

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 11:29:46 PM UTC  (a few moments ago)

File size:
92 KB (94,256 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\hotspot shield\bin\openvpnas.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/14/2009 4:00:00 AM

Valid to:
4/15/2011 3:59:59 AM

Subject:
CN=AnchorFree Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AnchorFree Inc, L=Sunnyvale, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3BD8C502DD23799E0549BD38965AA68D

File PE Metadata
Compilation timestamp:
6/1/2009 10:58:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.56

CTPH (ssdeep):
1536:ttFTIXzEVp4FCHYJ4s/qFo8xhABpJGMZchkCMDaM5TXLLHXDwfDXAbHjfzj0/vbC:tsImFYzxQZchkbDaM5TXLLHXDwfDXAbZ

Entry address:
0x1280

Entry point:
55, 89, E5, 83, EC, 08, C7, 04, 24, 01, 00, 00, 00, FF, 15, 7C, 94, 41, 00, E8, B8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 83, EC, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, 7C, 94, 41, 00, E8, 98, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 8B, 0D, B4, 94, 41, 00, 89, E5, 5D, FF, E1, 8D, 74, 26, 00, 55, 8B, 0D, 94, 94, 41, 00, 89, E5, 5D, FF, E1, 90, 90, 90, 90, 55, 89, E5, 5D, E9, E7, D5, 00, 00, 90, 90, 90, 90, 90, 90, 90, 55, 89, E5, 57, 56, 53, 81, EC, 7C, 03, 00, 00, 8B, 45, 10, C7...
 
[+]

Entropy:
6.3615

Packer / compiler:
MingWin32 - Dev C++ v4.x (h)

Code size:
72 KB (73,728 bytes)

Service
Display name:
Hotspot Shield Service

Service name:
HotspotShieldService

Type:
Win32OwnProcess, InteractiveProcess

Depends on:
tapvpn Dhcp


Scan openvpnas.exe - Powered by Reason Core Security