ti_10.0_heps_downloader.exe

Trend Micro Titanium

Trend Micro, Inc.

Publisher:
Trend Micro Inc.  (signed by Trend Micro, Inc.)

Product:
Trend Micro Titanium

Description:
Trend Micro Installer

Version:
9.0.0.1150

MD5:
e38f61f8b91847a867ed64e8509569c2

SHA-1:
0bf4a7a47ad5494ba2e89f3fc95396199ee807fa

SHA-256:
1e3e6a7d595c5258ea9868cd782d0b42db6f7768bb49b30359dfbe1e236ec95f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/3/2024 9:13:01 AM UTC  (today)

File size:
6.6 MB (6,924,712 bytes)

Product version:
10.0

Copyright:
Copyright (C) 2015 Trend Micro Incorporated. All rights reserved.

Trademarks:
Copyright (C) Trend Micro Inc.

Original file name:
7zsfx.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ti_10.0_heps_downloader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/19/2015 7:00:00 PM

Valid to:
5/21/2016 7:59:59 PM

Subject:
CN="Trend Micro, Inc.", O="Trend Micro, Inc.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1519396EE230F02CAD1FCFDB077A35F0

File PE Metadata
Compilation timestamp:
7/16/2015 12:42:18 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
98304:Ll3U2whYEO9wo43Em5Y9nuIcr99vwo9x14b0ghQyAeq/A:Ll0K9w/XQnrQvwo9x1C0UQ

Entry address:
0x84292

Entry point:
E8, 55, C1, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 10, 4A, 4F, 00, 75, 02, F3, C3, E9, 6C, 0A, 00, 00, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, AC, 2E, 50, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 7C, 4A, 4F, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, AC, 2E, 50, 00, 00, 0F, 83, A7, 01...
 
[+]

Entropy:
7.1968

Code size:
785.5 KB (804,352 bytes)

The file ti_10.0_heps_downloader.exe has been seen being distributed by the following 33 URLs.

http://wgt.digitalriver.com/wgt/9B5A4FCEF11DA80C/848D2212DBC2D52049A7D6CC7B487DAC3E716A25DE9847FD72F8F49E3E4EF71E49D745CCD0194FF47498D04DF45E608CDBB90AAC524563A0B0F32ED60EFC7A65653CF2089D3D174426C66E540322087A75FD63A7139E299A97A693A7BBF30D56/.../Ti_10.0_HEPS_Downloader.exe

http://wgtot71.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B26D643B52F5367582AAB4B7F3478ADE5E9038C239C2E64FF18CC76DAA9B61FCA020AC7324971AEE509750EB36F49A5823B426B2E44E99F5CC5336F931E20B3180A7DE0793B014624647C638FDE4F6D4D/.../Ti_10.0_HEPS_Downloader.exe

http://wgtot71.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7BD6E4B9979C1583E44CBBFA26DEF6DAC6DC3DE30E2F1090E6B80637D2B37723ADC8A9E4713D76D1B518A2E699CCCB6F1BA8D5275DC1F5B7C8E4F59E511A622B215C301D4CF6797C8A/.../Ti_10.0_HEPS_Downloader.exe

http://wgtot05.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7BD631DBCAB71A7B423067E995582108FF2C92458F956BCE0733F97306F36DC4F138A012CA299F054580E297312C2B63DAA9AEF68B19390434DD36D9D35AC370965C301D4CF6797C8A/.../Ti_10.0_HEPS_Downloader.exe

http://wgtot71.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B26D643B52F5367583D3A1E814AA257048F0459DC94659566573FC55F651EC5B603D647915E7A851E05B7617DEA9C0685E5861083B9F102B52BB81EC1E75FBF4C0A7DE0793B014624647C638FDE4F6D4D/.../Ti_10.0_HEPS_Downloader.exe

http://wgtot71.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B26D643B52F536758570553716843FD0ACB7F19B9B1790739FAFFE1D3FD210FB056A69BD7EF60655DB190B0CCC6FC972A47A1120FF2138294100096760D04006C0A7DE0793B014624647C638FDE4F6D4D/.../Ti_10.0_HEPS_Downloader.exe

http://wgtot71.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7BEDDF19CF2907C8488BFCDDACC89491E481BF0AE9C86F9226308189DD9AD42090D26F13122CCF578D8E5E317413DEB13F6D5E3CF228D6C114B0864DD48F71F9145C301D4CF6797C8A/.../Ti_10.0_HEPS_Downloader.exe

http://wgtot05.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7BD631DBCAB71A7B42E26D67947176BB545FC14D81D686E1F657D7C3FFB03C81E4A745BE73FF9FA40C2060A6FAF9CCAD4EE5878A8EF1988C1E301F871C22BA1A7D5C301D4CF6797C8A/.../Ti_10.0_HEPS_Downloader.exe

http://wgtot29.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7BB4812F5728912FFB2B6D2983E0AD920DAD2EA4C8916019299B2396F243EC91EE0D04EE43AB756DC358162E4DC9E4E1A5BF1A3274FE932BF22690E60CE53908038F5DC70B1E40C906/.../Ti_10.0_HEPS_Downloader.exe

http://wgtot05.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7BD631DBCAB71A7B42195D1F6365C26AE295BB89FFE4836C7B3A4D1685CC25844A03CF22FA0612B66EA5100D611AB406DAA11154845887177128F18B76DDB8E1005C301D4CF6797C8A/.../Ti_10.0_HEPS_Downloader.exe

https://www.google.com/url?hl=en&q=http://wgtot05.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7BD631DBCAB71A7B423067E995582108FF64AA8576DC5F72DCDBEA8321DB9AE91C70E3DE271A27B6CA704FAE2FBAE0D4A338A984A7FA11395C251D0526C46DAECF5C301D4CF6797C8A/.../Ti_10.0_HEPS_Downloader.exe&source=gmail&ust=1466470920106000&usg=AFQjCNE9FUeIj-VosGgAHuYKu2nESLu3yw

http://wgtot71.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B26D643B52F5367583D3A1E814AA25704E9038C239C2E64FFA6E03D5D6EDBCE7A020AC7324971AEE504445267DFF74ED53B426B2E44E99F5CCBF51D318499305B0A7DE0793B014624647C638FDE4F6D4D/.../Ti_10.0_HEPS_Downloader.exe

http://wgtot71.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7BD6E4B9979C1583E48BFCDDACC89491E437DFBE2CF03DC8062D209D4FFAC53DD02F01BF0FF097DC11B02791CA12B4C1C104FB7FA77D4ED36FC10E4DEE1B31A1625C301D4CF6797C8A/.../Ti_10.0_HEPS_Downloader.exe

http://wgtot57.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7BF855DF5DEF6EFE1BF4BB6D2CB322F16E02177369A0AED0396154512391E78B2E05CD2FF7FA2AE4AA51704C17AC63F02F6EC9D67F97EA508E1CCC3FD6CEC786055C301D4CF6797C8A/.../Ti_10.0_HEPS_Downloader.exe

Latest 30 of 33 download URLs

Scan ti_10.0_heps_downloader.exe - Powered by Reason Core Security