tmp.10108-wincorrectword.exe

Maxi Gramar s.l.

Publisher:
Maxi Gramar s.l.  (signed and verified)

MD5:
9b06f629b652cc72d2b55c2fd38eebdb

SHA-1:
7e3bd2bbe9da7108f9499983876659bd075ea02b

SHA-256:
3d088cf2b535b0e8398059464e566ebddc2985a72df4d9dd4d44baa7e43f27eb

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/27/2024 2:55:49 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.DR.Dorgam
7.1.1

McAfee
Artemis!9B06F629B652
5600.6321

Vba32 AntiVirus
TrojanDropper.Dorgam
3.12.26.4

File size:
2.4 MB (2,525,800 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\tmp.10108-wincorrectword.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/14/2012 1:00:00 AM

Valid to:
1/14/2013 12:59:59 AM

Subject:
CN=Maxi Gramar s.l., O=Maxi Gramar s.l., STREET=Calle Diputacio 184, L=Barcelona, S=Barcelona, PostalCode=08011, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00939DBD55BBB5F3FFD0C32EDDC886C666

File PE Metadata
Compilation timestamp:
8/31/2011 9:20:55 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:aw1mxYpnxyeJ9AEFnsrxoR3OR+YN95DyiL3NiiRqNuWo0GD739a5:N10Yy4NFnGxTAYN9809Rq9o3D7Nm

Entry address:
0x2CDFF

Entry point:
E8, 63, 4E, 00, 00, E9, 79, FE, FF, FF, 83, 25, 74, 22, 45, 00, 00, C3, 8B, FF, 55, 8B, EC, 56, FF, 35, B8, C7, 44, 00, 8B, 35, B0, E1, 43, 00, FF, D6, 85, C0, 74, 21, A1, B4, C7, 44, 00, 83, F8, FF, 74, 17, 50, FF, 35, B8, C7, 44, 00, FF, D6, FF, D0, 85, C0, 74, 08, 8B, 80, F8, 01, 00, 00, EB, 27, BE, 58, EC, 43, 00, 56, FF, 15, 34, E1, 43, 00, 85, C0, 75, 0B, 56, E8, CD, 41, 00, 00, 59, 85, C0, 74, 18, 68, 48, EC, 43, 00, 50, FF, 15, 54, E1, 43, 00, 85, C0, 74, 08, FF, 75, 08, FF, D0, 89, 45, 08, 8B, 45...
 
[+]

Code size:
242.5 KB (248,320 bytes)

Scan tmp.10108-wincorrectword.exe - Powered by Reason Core Security