wotsocialhubinstallerru.exe

Overwolf Installer

Overwolf Ltd

This is a setup and installation application. The file has been seen being downloaded from download.overwolf.com.
Publisher:
Overwolf  (signed by Overwolf Ltd)

Product:
Overwolf Installer

Version:
1.30.4693.31582

MD5:
870212d960fb3f53f72d19cc3eff5c77

SHA-1:
b7e88862d78ee1f040e1eee1eb8cf7be9883f744

SHA-256:
ba90af096ef6a4a2d8641828742c402c89f1b8deed0050898b0f86985cd259d7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 10:38:39 PM UTC  (today)

File size:
1 MB (1,081,272 bytes)

Product version:
1.30.4693.31582

Copyright:
Copyright © Overwolf 2011

Original file name:
OWInstaller.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\wotsocialhubinstallerru.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/26/2011 5:00:00 AM

Valid to:
2/11/2014 4:59:59 AM

Subject:
CN=Overwolf Ltd, O=Overwolf Ltd, STREET=Halechi 27 st., L=Bnei Berak, S=Tel Aviv, PostalCode=51200, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
02E4635116A814330262E360005D60EB

File PE Metadata
Compilation timestamp:
11/6/2012 10:37:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:+WS4lQ8apkkkVFLhbwzLvd+Y0prg/dtkclQ8MT:hS4lxapkkkVFdbwzLvZ/dtNlxA

Entry address:
0xF4646

Entry point:
FF, 25, 54, 46, 4F, 00, 00, 00, 00, 00, 00, 00, 00, 00, 28, 46, 0F, 00, 00, 00, 00, 00, 00, 00, 00, 00, CB, 4A, 99, 50, 00, 00, 00, 00, 02, 00, 00, 00, 8C, 00, 00, 00, 78, 46, 0F, 00, 78, 28, 0F, 00, 52, 53, 44, 53, 28, 52, 5E, DE, C0, 53, 0E, 4B, B0, 8C, 1D, 47, B5, 98, 3F, 09, 01, 00, 00, 00, 43, 3A, 5C, 4F, 76, 65, 72, 77, 6F, 6C, 66, 5C, 53, 6F, 75, 72, 63, 65, 5C, 4F, 76, 65, 72, 77, 6F, 6C, 66, 5C, 49, 6E, 73, 74, 61, 6C, 6C, 65, 72, 4E, 65, 78, 74, 56, 65, 72, 5C, 53, 6F, 75, 72, 63, 65, 5C, 4F, 57...
 
[+]

Code size:
970 KB (993,280 bytes)

The file wotsocialhubinstallerru.exe has been seen being distributed by the following URL.

Scan wotsocialhubinstallerru.exe - Powered by Reason Core Security