Workshare.exe

Desktop

*.workshare.com

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WorkshareDesktop’.
Publisher:
Workshare  (signed by *.workshare.com)

Product:
Desktop

Description:
Workshare Desktop application

Version:
1.7.7.3467

MD5:
69b37519ab108762471f96f2b0347000

SHA-1:
101e83543f79c1aa4825e28a3600b78d29ac1e83

SHA-256:
51c99c5c076ec31e6f81e325f6e5cd2de9913ad5b1fc387810f64fd19df2dd54

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 1:44:10 AM UTC  (today)

File size:
3.1 MB (3,270,144 bytes)

Product version:
1.7.7.3467

Copyright:
Copyright 2013 Workshare

Original file name:
Workshare.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\workshare\workshare desktop\workshare.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
2/15/2013 8:11:22 PM

Valid to:
2/15/2014 8:11:22 PM

Subject:
CN=*.workshare.com, OU=Domain Control Validated

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B306369653EFC

File PE Metadata
Compilation timestamp:
10/17/2013 2:05:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:33H5f+MK8zIs8BptbAIsxpG7pqt0flWFeT8eemlv:xgfs8js/Gct0f

Entry address:
0x15DA38

Entry point:
E8, A6, 04, 00, 00, E9, 63, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, B0, 68, 6E, 00, 89, 0D, AC, 68, 6E, 00, 89, 15, A8, 68, 6E, 00, 89, 1D, A4, 68, 6E, 00, 89, 35, A0, 68, 6E, 00, 89, 3D, 9C, 68, 6E, 00, 66, 8C, 15, C8, 68, 6E, 00, 66, 8C, 0D, BC, 68, 6E, 00, 66, 8C, 1D, 98, 68, 6E, 00, 66, 8C, 05, 94, 68, 6E, 00, 66, 8C, 25, 90, 68, 6E, 00, 66, 8C, 2D, 8C, 68, 6E, 00, 9C, 8F, 05, C0, 68, 6E, 00, 8B, 45, 00, A3, B4, 68, 6E, 00, 8B, 45, 04, A3, B8, 68, 6E, 00, 8D, 45, 08, A3, C4, 68, 6E...
 
[+]

Entropy:
6.9230

Code size:
1.6 MB (1,634,816 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WorkshareDesktop

Command:
C:\Program Files\workshare\workshare desktop\workshare.exe


Scan Workshare.exe - Powered by Reason Core Security