tti_7.0_he_downloader.exe

Trend Micro Titanium

Trend Micro, Inc.

Publisher:
Trend Micro Inc.  (signed by Trend Micro, Inc.)

Product:
Trend Micro Titanium

Version:
7.0.0.1151

MD5:
ed220cde92c469aeeee9b1590543b723

SHA-1:
d3e56196cb3b556dabeb812e364eba0ce46a47c6

SHA-256:
47a232458709d13e5ac290c96f57f3acf8e6c4d34a188ccd155cf832f532abf4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 8:09:42 PM UTC  (today)

File size:
6.3 MB (6,631,496 bytes)

Product version:
7.0

Copyright:
Copyright (C) 2013 Trend Micro Incorporated. All rights reserved.

Trademarks:
Copyright (C) Trend Micro Inc.

Original file name:
7zsfx.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\tti_7.0_he_downloader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/16/2013 7:00:00 PM

Valid to:
3/18/2014 7:59:59 PM

Subject:
CN="Trend Micro, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Trend Micro, Inc.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A9D178AD334ACDF47C8A0D15BB50E6E

File PE Metadata
Compilation timestamp:
7/23/2013 9:45:33 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
98304:RVSI7IiC502sPzJUBV89XWkE2e9agy7hOEdiUyA61dew8e:RoI7E5hq28gkzDOTUyv1ME

Entry address:
0x76353

Entry point:
E8, B4, 70, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 50, C3, 4B, 00, 75, 02, F3, C3, E9, 6B, 0A, 00, 00, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 34, 95, 4C, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, BC, C3, 4B, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 34, 95, 4C, 00, 00, 0F, 83, A7, 01, 00...
 
[+]

Entropy:
7.0589

Code size:
605 KB (619,520 bytes)

The file tti_7.0_he_downloader.exe has been seen being distributed by the following 41 URLs.

http://wgtot25.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B839B6A266135AC0E2B6D2983E0AD920D35B149976B76BB9BC85505B0A4BE225664DE21C9D7A5D22C9DDB1E98A7B5410CC7A525149E9F24351CF47D266CF7E4178F5DC70B1E40C906/.../TTi_7.0_HE_Downloader.exe

http://wgtot25.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B79084777A8A3AEE12B6D2983E0AD920DAFB62B9A12C9F7411B78E1198A66ADA0561EE3DA265EDEC401262E411154DACE2DB0D25B20A890BBCA3E62C13A0C81098F5DC70B1E40C906/.../TTi_7.0_PS_Downloader.exe

http://wgtot24.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B263F0A79AAAB05948D273C5554AF20956FEBA3D65C28BC7B5C2628D847C96C696882E8D2C83143EE095FE3003E08D5E8C27D80CF82FD067B1A539068690CE1488F5DC70B1E40C906/.../TTi_7.0_HE_Downloader.exe

http://wgtot25.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B43233AB4C3497D902B6D2983E0AD920DA85444AE13CD1306AB9AD93BC50D2162263D8A0EC90BCC9B20D4F9E169DFA06A38B46FCD533D95A4324C17F93AB5D3B98F5DC70B1E40C906/.../TTi_7.0_HE_Downloader.exe

http://wgtot25.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B1FCD99672C7357262B6D2983E0AD920D6B9DD405532B37473324C493E1CA980867E352FBFE99D5C1621561C86EDF72E6AF286702B2C9F1EBCA05EF736BF46AE98F5DC70B1E40C906/.../TTi_7.0_PS_Downloader.exe

http://wgtot25.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7BD8E4E19EC23292D42B6D2983E0AD920D251CC7BC2050B289B5E486E071E2D183750C608A48336EF4C4632B853E574E0D808CC9D899B527A68999951E43D4316E8F5DC70B1E40C906/.../TTi_7.0_PS_Downloader.exe

http://wgtot25.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B537DC90F24167CE52B6D2983E0AD920D45EF22071AE34B0AB9EC7DE76EBA43CB7B41EE0928E31F8AEB62B5AD22601FE2FB41B82BAEDB3A2C917E560C785823BE8F5DC70B1E40C906/.../TTi_7.0_HE_Downloader.exe

http://wgtot25.digitalriver.com/wgt/9B5A4FCEF11DA80C/171F14235882A3D34841170D5B9DEF7B81FFE600757439E02B6D2983E0AD920DD2C1F0750FC530842490C44E62B133BF51AAB82C91E2C35A1F787B1B52EDDF0BD382DEB82E06C6731CF47D266CF7E4178F5DC70B1E40C906/.../TTi_7.0_PS_Downloader.exe

Latest 30 of 41 download URLs

Scan tti_7.0_he_downloader.exe - Powered by Reason Core Security