Workshare.exe

Desktop

*.workshare.com

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WorkshareDesktop’.
Publisher:
Workshare  (signed by *.workshare.com)

Product:
Desktop

Description:
Workshare Desktop application

Version:
1.7.7.3470

MD5:
20acc6aebc1e565a0a4730711e42ef64

SHA-1:
2964837c2557f871a0e759e27066180f16126d0e

SHA-256:
3f6a3a0caeaa47a820bf3b25fad5cad8b2dd56843ba4c66946b2f2403205069a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:00:16 PM UTC  (today)

File size:
3.1 MB (3,268,608 bytes)

Product version:
1.7.7.3470

Copyright:
Copyright 2013 Workshare

Original file name:
Workshare.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\workshare\workshare desktop\workshare.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
2/15/2013 9:41:22 AM

Valid to:
2/15/2014 9:41:22 AM

Subject:
CN=*.workshare.com, OU=Domain Control Validated

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B306369653EFC

File PE Metadata
Compilation timestamp:
10/22/2013 9:25:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:XoyTTX1SV91fHqAnsxpGTVEQ2d/8Ecte7qloY3e:7hS91s/GRE

Entry address:
0x15D938

Entry point:
E8, A6, 04, 00, 00, E9, 63, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 90, 58, 6E, 00, 89, 0D, 8C, 58, 6E, 00, 89, 15, 88, 58, 6E, 00, 89, 1D, 84, 58, 6E, 00, 89, 35, 80, 58, 6E, 00, 89, 3D, 7C, 58, 6E, 00, 66, 8C, 15, A8, 58, 6E, 00, 66, 8C, 0D, 9C, 58, 6E, 00, 66, 8C, 1D, 78, 58, 6E, 00, 66, 8C, 05, 74, 58, 6E, 00, 66, 8C, 25, 70, 58, 6E, 00, 66, 8C, 2D, 6C, 58, 6E, 00, 9C, 8F, 05, A0, 58, 6E, 00, 8B, 45, 00, A3, 94, 58, 6E, 00, 8B, 45, 04, A3, 98, 58, 6E, 00, 8D, 45, 08, A3, A4, 58, 6E...
 
[+]

Entropy:
6.9246

Code size:
1.6 MB (1,634,304 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WorkshareDesktop

Command:
C:\users\{user}\appdata\local\workshare\workshare desktop\workshare.exe


Scan Workshare.exe - Powered by Reason Core Security