windows__4b1f2f20-19b1-420e-8a45-ff2539d5b74f__.exe

AT&T

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from pattsmpii.att.motive.com and multiple other hosts.
Publisher:
AT&T  (signed and verified)

MD5:
a80564ec79fb1452df3e1b889574f6ad

SHA-1:
3059e64e7ef2962444d0eacfdab1ade186d4eb65

SHA-256:
1fb6fcdb735e2ff586b1167f50621b9aca0c4a4d88001899e7951b0864f4d5bb

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 9:21:32 AM UTC  (today)

File size:
91.8 KB (94,016 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\windows__4b1f2f20-19b1-420e-8a45-ff2539d5b74f__.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/10/2011 7:00:00 PM

Valid to:
10/10/2014 6:59:59 PM

Subject:
CN=AT&T, OU=AT&T Mass Market Care Application, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AT&T, L=Austin, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
450BA65F1A924BBA80F3ADFB4024A31A

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:VpgpHzb9dZVX9fHMvG0D3XJIGOMbdpSOEoJEdGUZWBfndo2of2FcrspFI9V:HgXdZt9P6D3XJ62dAOEo4/ZWBfipOCrB

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.0068

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file windows__4b1f2f20-19b1-420e-8a45-ff2539d5b74f__.exe has been seen being distributed by the following 50 URLs.

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__7bb5f4d1-a045-4b9f-a5a7-e136b3f4374f__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__c5305431-1080-4990-a5bb-87071fab9e13__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__e5faff83-1054-4828-9b31-090f218f9013__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__4cf5be71-ac1d-446e-99df-f392edfa18f7__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__1c96e643-0cf3-4d07-9b81-7f304ecc065e__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__e1f1f3b7-2691-4511-be57-45b4d34d1231__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__03a78ce9-8de5-494c-a17a-1b2cc891c515__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__89331244-b55c-473d-8a9b-276f821aa8d9__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__db58b8e9-f935-4f78-a740-77c0e2075dbe__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__9b574755-481b-47e3-a5ce-b53a037f4d19__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__1fa8b2e1-8934-4ab9-8b06-11cf6fc8537d__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__69289646-ad88-4281-91be-c8354a535b20__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__2d9bdfb7-c16f-4254-9926-cad268daa00e__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__3f9821af-44ee-4522-84c2-82101d6af42a__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__1efaad53-f71f-48b8-adf7-7335eec81d65__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__1fdc4679-803a-4e12-a318-351d85bb9d3f__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__fd524713-34eb-4f73-8468-a1b6aae28a4a__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__28f476ce-f23a-41da-859c-d3b693e77f4d__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__f119c675-50f1-4937-b5df-95261b0a077d__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__50943bd6-b589-4108-81f8-4bca5bff2b88__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__2d6c2409-04ed-44c0-a942-6eb67a79d8b3__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__d38e12af-1956-4b85-ae89-ef282a516199__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__9b2f37bd-3147-4752-b9f4-20c358341ea2__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__37126f98-56bd-4da2-b7d7-41c3e25aff35__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__59a7bae2-11f6-4cdb-a208-34681e9c774b__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__0b73b3e4-0844-4ef0-8e6f-398ce7b4fc6c__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__2cfc747a-14fa-42c8-854d-dda2ddcbd4d4__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__ead6b4b9-6d82-44cf-a2d2-ce003876a92f__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__615f6f26-f0d2-477b-a498-bad230662135__.exe

https://pattsmpii.att.motive.com/homeview/activation/client/.../windows__599a0991-d3aa-46d7-be39-fb60f1ef1c83__.exe

Latest 30 of 159 download URLs