OPT_SECS.EXE

OPTENET Security Suite

Optenet, S.A.

It runs as a windows Service named “OPTENET PC Web Filter”.
Publisher:
OPTENET  (signed by Optenet, S.A.)

Product:
OPTENET Security Suite

Version:
10,9,70,0

MD5:
72fc6ce5a8eee3b946bd357b3057476f

SHA-1:
8d8291c58c3e7f682f83dae96eaa1bcf81e8c278

SHA-256:
72dcea9fec68fdb1a9db725ed465a4a8f3fa4032febb2d10d84fe135eaaed0c7

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 10:36:11 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
probably DLOADER.Trojan
9.0.1.05190

File size:
1 MB (1,096,752 bytes)

Product version:
10,9,70,0

Copyright:
Copyright © 2009

Original file name:
OPT_SECS.EXE

File type:
Executable application (Win32 EXE)

Language:
Spanish

Common path:
C:\Program Files\optenet pc web filter\bin\opt_secs.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
12/5/2012 1:00:00 AM

Valid to:
2/8/2016 1:00:00 PM

Subject:
CN="Optenet, S.A.", O="Optenet, S.A.", L=Las Rozas de Madrid, S=me, C=ES

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0A8CF2F43A59FD56CF56A37B29CDDB3F

File PE Metadata
Compilation timestamp:
12/12/2012 12:13:58 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:OzIPgJiPdkbwEcmCmyO/cULMAtrHCkfLooXXqBw1:OzIPK2kbwBFO/bLHrHCkfLjXXqBw1

Entry address:
0x93965

Entry point:
E8, 9B, F3, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 57, 33, DB, 6A, 07, 33, C0, 59, 8D, 7D, E4, 89, 5D, E0, F3, AB, 39, 5D, 10, 75, 18, E8, 89, CC, FF, FF, C7, 00, 16, 00, 00, 00, E8, BF, 58, 00, 00, 83, C8, FF, E9, 96, 00, 00, 00, 8B, 45, 0C, 56, 8B, 75, 08, 3B, C3, 74, 19, 3B, F3, 75, 15, E8, 62, CC, FF, FF, C7, 00, 16, 00, 00, 00, E8, 98, 58, 00, 00, 83, C8, FF, EB, 71, C7, 45, EC, 42, 00, 00, 00, 89, 75, E8, 89, 75, E0, 3D, FF, FF, FF, 3F, 76, 09, C7, 45, E4, FF, FF, FF, 7F, EB...
 
[+]

Entropy:
6.6379

Code size:
725 KB (742,400 bytes)

Service
Display name:
OPTENET PC Web Filter

Type:
Win32OwnProcess, InteractiveProcess

Group:
NetworkProvider


Scan OPT_SECS.EXE - Powered by Reason Core Security