PDAMessageFetcher.exe

PDA Message Fetcher

Angel Broking Pvt. Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PDAMessageFetcher’.
Publisher:
Angel Broking Ltd.  (signed by Angel Broking Pvt. Ltd.)

Product:
PDA Message Fetcher

Version:
1.00

MD5:
b673d199f203e110a87cfa7b7639c3a3

SHA-1:
8620a1340ac0377afeb4622fb50aa07eb6c7f199

SHA-256:
418170401b12bac404f49f9341badd6fc446f00fba146018272050ba5adebe79

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 12:26:41 AM UTC  (today)

File size:
49.9 KB (51,080 bytes)

Product version:
1.00

Copyright:
Angel Broking

Original file name:
PDAMessageFetcher.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/24/2012 5:30:00 AM

Valid to:
7/25/2015 5:29:59 AM

Subject:
CN=Angel Broking Pvt. Ltd., OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Angel Broking Pvt. Ltd., L=Mumbai, S=Maharashtra, C=IN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6019FB7B5730892D25D00FA6C56F81B3

File PE Metadata
Compilation timestamp:
2/16/2010 12:16:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:K3f8SdxnY1Xzi8+/SzkOU9ifwiDEANEEIILUI:K3fBXY1XzmSzkP9ifwihNEEYI

Entry address:
0x1650

Entry point:
68, 10, 1F, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, 2A, C7, 7C, 13, 4A, CA, 64, 42, 9E, 92, 3A, AC, EB, 9B, 49, 0E, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 50, 44, 41, 4D, 65, 73, 73, 61, 67, 65, 46, 65, 74, 63, 68, 65, 72, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 05, CE, 99, C1, 89, A4, 86, 87, 41, 8A, CC, B1, 34, 45, 88, 10, 50, 2E, F9, 13, B6, 70, 6B, 04, 44, AF, BB, A9, 55, 45, 28, 6E, 8C, 3A, 4F, AD...
 
[+]

Entropy:
5.2097

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
32 KB (32,768 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PDAMessageFetcher

Command:
C:\angel pda7\pdamessagefetcher.exe


Scan PDAMessageFetcher.exe - Powered by Reason Core Security