pdoubledecker.exe

MagicRAR

Publisher:
MagicRAR  (signed and verified)

MD5:
c4c13600b36866f43eed927be6ab2e0d

SHA-1:
fb38155aad404f7e5f444a21836c3c36d7ed9608

SHA-256:
fa5b4ded9c8fa4430c9f22a3446c57c896f8bbc63c6e510b0d8a59ce096351dc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 5:17:25 PM UTC  (today)

File size:
1.5 MB (1,563,104 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\{46994f3f-c4f2-482e-a8fa-ab9091043bf4}\offline\6d542c07\bcf3ddcb\pdoubledecker.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
8/20/2012 2:09:34 AM

Valid to:
8/20/2013 2:09:34 AM

Subject:
E=rarmagic@gmail.com, CN="Open Source Developer,Simon KING", O=MagicRAR, C=US

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
4FBB8FD1224917F1AEF6D267E38EFB3E

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:jCTC4w0Y+fSfwIL3VPAdbO/RDFhBpEIQKQEkJ/smk0pSldSkzkCM1yoXkxvfKVzT:jCTSCfSXJPAJO/RDFhMdMQYL1wgY

Entry address:
0xC0084

Entry point:
55, 8B, EC, 83, C4, EC, 53, 33, C0, 89, 45, EC, B8, C4, FB, 4B, 00, E8, 4E, 71, F4, FF, 8B, 1D, 80, 53, 4C, 00, 33, C0, 55, 68, 62, 01, 4C, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, 33, C0, E8, 0C, 2F, F4, FF, 8B, 45, EC, E8, 10, 5A, FB, FF, 8B, 03, E8, F5, EA, F8, FF, 8B, 03, BA, 78, 01, 4C, 00, E8, D1, E6, F8, FF, 8B, 0D, 30, 54, 4C, 00, 8B, 03, 8B, 15, 58, F7, 4B, 00, E8, EE, EA, F8, FF, 8B, 0D, A4, 52, 4C, 00, 8B, 03, 8B, 15, AC, 9F, 4B, 00, E8, DB, EA, F8, FF, 8B, 0D, 9C, 55, 4C, 00, 8B, 03, 8B, 15, E4...
 
[+]

Entropy:
6.0103

Developed / compiled with:
Microsoft Visual C++

Code size:
764.5 KB (782,848 bytes)

Scan pdoubledecker.exe - Powered by Reason Core Security