Updater.exe

Espresso Auto Updater

Blue Mountain Soft, Inc.

Publisher:
Blue Mountain Soft(TM), Inc.  (signed by Blue Mountain Soft, Inc.)

Product:
Espresso Auto Updater

Version:
1.1.2.1

MD5:
923c5bcbdba4eeb16b26448004d9ca64

SHA-1:
f181dd14f112284d19bc44787dea5ca5de63d881

SHA-256:
2a8cbb2a0d3a8a4e67f6c8dcab7a2725d1da5396eb0113ef6a889cf69bba2cc9

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/26/2024 3:15:40 PM UTC  (today)

Scan engine
Detection
Engine version

Vba32 AntiVirus
suspected of Trojan-Clicker.Agent.16
3.12.26.3

File size:
169.2 KB (173,296 bytes)

Product version:
1.1.2.1

Copyright:
Copyright (C) 2007-2009 Blue Mountain Soft(TM), Inc.

Original file name:
Updater.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\blue mountain soft\espresso xdf\reader\updater.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Subject:
CN="Blue Mountain Soft, Inc.", O="Blue Mountain Soft, Inc.", L=Yeongdeungpo-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
04638A5E8970237907826A38F0B2677F

File PE Metadata
Compilation timestamp:
12/21/2009 11:08:20 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:ocOSAjDLK/tJMYgML8GQrS8f+bf5YwoZaLh9yJ8WaY4421ZDyaay7ConnE:VOotcML8GQt+a61WX4421ZxFzE

Entry address:
0x16E5F

Entry point:
55, 8B, EC, 6A, FF, 68, 68, B7, 41, 00, 68, CA, 6F, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 60, A5, 41, 00, 59, 83, 0D, 98, 21, 42, 00, FF, 83, 0D, 9C, 21, 42, 00, FF, FF, 15, 5C, A5, 41, 00, 8B, 0D, 7C, 21, 42, 00, 89, 08, FF, 15, 58, A5, 41, 00, 8B, 0D, 78, 21, 42, 00, 89, 08, A1, 54, A5, 41, 00, 8B, 00, A3, 94, 21, 42, 00, E8, 29, 01, 00, 00, 39, 1D, B0, 1D, 42, 00, 75, 0C, 68, F4, 6F, 41, 00, FF, 15, 50, A5...
 
[+]

Entropy:
5.9565

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
100 KB (102,400 bytes)

The file Updater.exe has been seen being distributed by the following URL.

Scan Updater.exe - Powered by Reason Core Security