safe2012int_chip.exe

Steganos Product Downloader 1

Steganos Software GmbH

Publisher:
Steganos Software GmbH  (signed and verified)

Product:
Steganos Product Downloader 1

Description:
Steganos Product Downloader

Version:
1.0.0.9996

MD5:
b4e7e113d8b71f791f97b0864b1ddc34

SHA-1:
f052619265459bee89c50f28ae588bdb392b66a9

SHA-256:
6379d3b4f37754b30005513f3bbaf4c755a49f22478913811a6a1a13b3a757ec

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/26/2024 6:41:37 PM UTC  (today)

Scan engine
Detection
Engine version

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

File size:
2.3 MB (2,450,128 bytes)

Product version:
1.0.0.9996

Copyright:
Copyright (c) 2010 Steganos GmbH

Trademarks:
Steganos Product Downloader 1 is a trademark of Steganos GmbH

Original file name:
ProductDownloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\safe2012int_chip.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/3/2010 3:55:52 PM

Valid to:
9/3/2012 3:55:48 PM

Subject:
E=certificates@steganos.com, CN=Steganos Software GmbH, O=Steganos Software GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012AD816B401

File PE Metadata
Compilation timestamp:
3/8/2012 5:30:52 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:YRS0N7Tyk8r4qNIcWq0PsA43UKCTeE5Jpg:InSkCIOA4Ef/p

Entry address:
0x16A356

Entry point:
E8, B3, 1F, 01, 00, E9, 78, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 68, 24, 63, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 68, 24, 63, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
6.5588

Code size:
1.7 MB (1,755,136 bytes)

The file safe2012int_chip.exe has been seen being distributed by the following URL.

Scan safe2012int_chip.exe - Powered by Reason Core Security