workspaceinstall_pl.exe

ValiCert, Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from na.secureserver.net.
Publisher:
ValiCert, Inc.  (signed and verified)

MD5:
43b3b65d3aa1234a916636204569b304

SHA-1:
0292afb320020879cb2321cf8de303a5ad3b1265

SHA-256:
87245e9a8ce3dcd474b65c061d45cae85362e84729e7c8cd7b117a941cddd2c2

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/7/2024 8:16:00 PM UTC  (today)

Scan engine
Detection
Engine version

Sophos
Virus 'Mal/Krap-K'
5.23

File size:
902.6 KB (924,212 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\workspaceinstall_pl.exe

Digital Signature
Signed by:

Authority:
ValiCert, Inc.

Valid from:
6/25/1999 7:19:54 PM

Valid to:
6/25/2019 7:19:54 PM

Subject:
E=info@valicert.com, CN=http://www.valicert.com/, OU=ValiCert Class 2 Policy Validation Authority, O="ValiCert, Inc.", L=ValiCert Validation Network

Issuer:
E=info@valicert.com, CN=http://www.valicert.com/, OU=ValiCert Class 2 Policy Validation Authority, O="ValiCert, Inc.", L=ValiCert Validation Network

Serial number:
01

File PE Metadata
Compilation timestamp:
10/20/2014 2:55:54 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:T6CkIslLBlMBhLgFNdbCEuFzD2jT3EcLK:TZDBpK3CEuRGT3FK

Entry address:
0x512D3

Entry point:
80, C8, 00, 00, 00, 8B, 4D, 08, 0F, B7, 04, 48, 25, 17, 01, 00, 00, 80, 7D, FC, 00, 74, 07, 8B, 4D, F8, 83, 61, 70, FD, C9, C3, 8B, FF, 55, 8B, EC, 83, 3D, 0C, 9C, 48, 00, 00, 75, 14, 8B, 45, 08, 8B, 0D, 70, 26, 48, 00, 0F, B7, 04, 41, 25, 17, 01, 00, 00, 5D, C3, 6A, 00, FF, 75, 08, E8, 7E, FF, FF, FF, 59, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 3C, 53, FF, 75, 08, 8D, 4D, C4, E8, 57, C1, FF, FF, 8B, 4D, 10, 8B, 45, 0C, 33, DB, 3B, CB, 74, 02, 89, 01, 3B, C3, 75, 25, E8, 1A, D8, FF, FF, C7, 00, 16, 00, 00...
 
[+]

Code size:
422 KB (432,128 bytes)

The file workspaceinstall_pl.exe has been seen being distributed by the following URL.

Scan workspaceinstall_pl.exe - Powered by Reason Core Security