pcc2016_he_full.exe

Trend Micro Titanium

Trend Micro, Inc.

This is a setup and installation application. The file has been seen being downloaded from wgtot59.digitalriver.com and multiple other hosts.
Publisher:
Trend Micro Inc.  (signed by Trend Micro, Inc.)

Product:
Trend Micro Titanium

Description:
Trend Micro Installer

Version:
9.0.0.1150

MD5:
dbd75ad5d3c76027b279de575dcd1708

SHA-1:
3b5c25f1b66e6cae3a4a69d801dc5bf2958681df

SHA-256:
0e6068807da78b1f18963e2f48dd10166556de032cd45446aef00df6083027e5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:20:00 AM UTC  (today)

File size:
211.7 MB (221,971,488 bytes)

Product version:
10.0

Copyright:
Copyright (C) 2015 Trend Micro Incorporated. All rights reserved.

Trademarks:
Copyright (C) Trend Micro Inc.

Original file name:
7zsfx.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\pcc2016_he_full.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/20/2015 8:00:00 AM

Valid to:
5/22/2016 7:59:59 AM

Subject:
CN="Trend Micro, Inc.", O="Trend Micro, Inc.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1519396EE230F02CAD1FCFDB077A35F0

File PE Metadata
Compilation timestamp:
7/17/2015 12:42:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6291456:UntGxacDKx3leVzaVJFdRdVpcrpk2akm6qpVc1LulbTu7:+GxQxkEJFdvVpctAlXpwLulvE

Entry address:
0x84292

Entry point:
E8, 55, C1, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 10, 4A, 4F, 00, 75, 02, F3, C3, E9, 6C, 0A, 00, 00, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, AC, 2E, 50, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 7C, 4A, 4F, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, AC, 2E, 50, 00, 00, 0F, 83, A7, 01...
 
[+]

Entropy:
7.9967  (probably packed)

Code size:
785.5 KB (804,352 bytes)

The file pcc2016_he_full.exe has been seen being distributed by the following 8 URLs.

http://wgtot59.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B6DDCA752C3C57D42218702A067F2AB95180E08DADDC704B7CDBD5B073304717CD60021B2403A50053A52850270CC2AF4FFF9B10E403F71EEEC7C8FA532DA646E0A7DE0793B014624647C638FDE4F6D4D/.../TW_PCC2016_HE_Full.exe

http://wgtot59.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B6DDCA752C3C57D42B2534669DAB2F3ED88940F3E31DE50AFD1DA374770CFD1262517EB92605C0FE2005BFCC1AD73D53D9D6336C76FDCED624F24EEECA71C78D80A7DE0793B014624647C638FDE4F6D4D/.../TW_PCC2016_HE_Full.exe

http://wgtot59.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B2162071CF167A36B8D273C5554AF20958147BAC9E6BB5F140704E14044B5EF0E5735C492EE683EEC785E0A415AE8A8AF269237DF1419F27DBA48573ED301DB4B8F5DC70B1E40C906/.../TW_PCC2016_HE_Full.exe

http://wgtot59.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B6DDCA752C3C57D425A50DA7A80F10B0E6336688C77D5B5CFC7CDFC840389DF267C838592EF99B5AA0DC41EF1CF80D7FB0F0BDA6F37A190874AD87C040005D9A50A7DE0793B014624647C638FDE4F6D4D/.../TW_PCC2016_HE_Full.exe

http://wgtot59.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B6DDCA752C3C57D423D2BAC70F0A0FF13A6156AB8A194E24384A273C6BCEEE61B68E9F6CD332FBBF6B675102BCAC0000D0F0BDA6F37A190870390BE1B5FF798E90A7DE0793B014624647C638FDE4F6D4D/.../TW_PCC2016_HE_Full.exe

Scan pcc2016_he_full.exe - Powered by Reason Core Security