VASAC.exe

Virtual Assist Stand Alone Client

SonicWALL Inc.

Publisher:
SonicWALL Inc  (signed by SonicWALL Inc.)

Product:
Virtual Assist Stand Alone Client

Version:
3.5.1.18

MD5:
a3a943c1f9d8138acef296b598bcd796

SHA-1:
964c98d4d4a1ea5dbc63ea3f99e7002a217b006f

SHA-256:
c9dc401d2e2f6ad2ab81e6e65b23d56f96d924aa9c786a68e91a135c792555ec

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/16/2024 6:06:17 PM UTC  (today)

File size:
1.1 MB (1,124,224 bytes)

Product version:
3.5.1.18

Copyright:
Copyright (C) 2008-2010 SonicWALL Inc. All rights reserved.

Original file name:
VASAC.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vasac.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/27/2009 7:00:00 AM

Valid to:
7/27/2012 6:59:59 AM

Subject:
CN=SonicWALL Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SonicWALL Inc., L=Sunnyvale, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
75FA0F2F2B7887AEFA70ED84AC4900F9

File PE Metadata
Compilation timestamp:
6/30/2010 12:58:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:amY+X9IlOirLRDpdyU57vqG3WTjsOq3AYn4Wyi8NSZsn7j/OK0nWuejaa8ur5xRG:amYk4JX7vdW3sOq3AYn4WyikSZsn7j/I

Entry address:
0x87CD0

Entry point:
55, 8B, EC, E8, C8, 1F, 01, 00, E8, 03, 00, 00, 00, 5D, C3, CC, 55, 8B, EC, 6A, FE, 68, E8, 51, 4D, 00, 68, C0, D4, 48, 00, 64, A1, 00, 00, 00, 00, 50, 81, C4, 78, FF, FF, FF, 53, 56, 57, A1, 9C, E4, 4D, 00, 31, 45, F8, 33, C5, 50, 8D, 45, F0, 64, A3, 00, 00, 00, 00, 89, 65, E8, C7, 45, 88, 00, 00, 00, 00, C7, 85, 74, FF, FF, FF, 00, 00, 00, 00, C7, 45, E4, 00, 00, 00, 00, C7, 45, 80, 00, 00, 00, 00, C7, 85, 7C, FF, FF, FF, 00, 00, 00, 00, C7, 85, 78, FF, FF, FF, 00, 00, 00, 00, C7, 45, FC, 00, 00, 00, 00...
 
[+]

Entropy:
6.4168

Developed / compiled with:
Microsoft Visual C++

Code size:
700 KB (716,800 bytes)

The file VASAC.exe has been seen being distributed by the following 3 URLs.

https://192.168.168.168/customerLaunch.html

Scan VASAC.exe - Powered by Reason Core Security