psafeweb.exe

PSafe Internet

PSafe Tecnologia S.A.

This is a setup program which is used to install the application. The file has been seen being downloaded from instalar.psafe.com and multiple other hosts.
Publisher:
PSafe Tecnologia S.A.  (signed and verified)

Product:
PSafe Internet

Version:
7.5.2.130

MD5:
7cc0c77b241ea137ad84ee253de4ca0d

SHA-1:
a8ff92cd0be3c00048fd89f6136bf0e34e569270

SHA-256:
392f73d2f452bca54a78af08dc0e284d0ed6d121db27b1ef514ac65c6c4ae049

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 2:19:12 AM UTC  (today)

File size:
46.8 MB (49,121,120 bytes)

Product version:
7.5.2.130

Copyright:
(C) PSafe Tecnologia S.A.

File type:
Executable application (Win32 EXE)

Language:
Portuguese (Brazil)

Common path:
C:\Program Files\psafe\total\psafe\psafeweb.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/20/2013 9:00:00 PM

Valid to:
1/26/2015 9:00:00 AM

Subject:
CN=PSafe Tecnologia S.A., O=PSafe Tecnologia S.A., L=Rio de Janeiro, S=Rio de Janeiro, C=BR

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07F79AA9335B794D70779F719061AFF2

File PE Metadata
Compilation timestamp:
8/16/2014 8:17:24 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
786432:HxEgmN5O/YfsTf/kjS0C2pbxxn/1FSjYrpwjLr8aJk1DvTmeLhC:RS5O/YfsjQS0vpbxxn/14jYVwj1S1DLM

Entry address:
0x90C1

Entry point:
E8, 63, 5E, 00, 00, E9, 89, FE, FF, FF, 83, 25, 28, 7E, 41, 00, 00, C3, 3B, 0D, 8C, 50, 41, 00, 75, 02, F3, C3, E9, E2, 5E, 00, 00, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, D0, 67, 41, 00, FF, 15, 30, 10, 40, 00, 85, C0, 75, 18, 56, E8, FD, 12, 00, 00, 8B, F0, FF, 15, 90, 10, 40, 00, 50, E8, AD, 12, 00, 00, 59, 89, 06, 5E, 5D, C3, 57, 8B, C6, 83, E0, 0F, 85, C0, 0F, 85, C1, 00, 00, 00, 8B, D1, 83, E1, 7F, C1, EA, 07, 74, 65, EB, 06, 8D, 9B, 00, 00, 00, 00, 66, 0F, 6F, 06, 66...
 
[+]

Code size:
77.5 KB (79,360 bytes)

The file psafeweb.exe has been seen being distributed by the following 2 URLs.

Scan psafeweb.exe - Powered by Reason Core Security