tobi.exe

Cornelsen Verlag GmbH & Co. OHG

Publisher:
Cornelsen Verlag  (signed by Cornelsen Verlag GmbH & Co. OHG)

Description:
Tobi - Digitaler Unterrichtsplaner

Version:
1.0.0.0

MD5:
13fbed7b8d255328e7ea090df8c5979f

SHA-1:
3df839cc49d8706452707f85ce0a6101a7741594

SHA-256:
fd6b647c9892c8f34f14eccfa2a414ccd0aa36bbf8abd36e14eb52eeb7ad1bc9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 6:38:31 PM UTC  (today)

File size:
4.2 MB (4,384,040 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\tobi.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/12/2007 8:00:00 PM

Valid to:
7/13/2010 7:59:59 PM

Subject:
CN=Cornelsen Verlag GmbH & Co. OHG, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Cornelsen Verlag GmbH & Co. OHG, L=Berlin, S=Berlin, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
462C1CE680C27FD6F647948F7566F39A

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:y3T6Uq1IM1SkZTIOq4pkghHLB42XiCyjn02J8lHL18iILZ4S+/:Y2FakZpg242Xcj024r+iIl4S0

Entry address:
0x1438D8

Entry point:
55, 8B, EC, 83, C4, E0, 53, 33, C0, 89, 45, E4, 89, 45, E0, 89, 45, EC, 89, 45, E8, B8, 28, 33, 54, 00, E8, 35, 3A, EC, FF, 33, C0, 55, 68, 70, 3B, 54, 00, 64, FF, 30, 64, 89, 20, 33, DB, BA, 80, 3B, 54, 00, B8, A4, 3B, 54, 00, E8, EA, 9C, FE, FF, 0A, D8, 84, DB, 0F, 85, 35, 02, 00, 00, A1, 24, A1, 54, 00, E8, D2, 15, EC, FF, A1, 98, A0, 54, 00, C6, 00, 01, E8, 61, D2, F2, FF, 84, C0, 74, 0D, E8, 30, D0, F2, FF, 84, C0, 0F, 85, 0D, 02, 00, 00, E8, 6B, A2, FE, FF, 8D, 45, E8, E8, F7, 87, FE, FF, 8B, 45, E8...
 
[+]

Entropy:
7.7294

Developed / compiled with:
Microsoft Visual C++

Code size:
1.3 MB (1,321,984 bytes)

Scan tobi.exe - Powered by Reason Core Security