wow_patched.exe

World of Warcraft

Blizzard Entertainment, Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from repo.midgar-online.com.
Publisher:
Blizzard Entertainment  (signed by Blizzard Entertainment, Inc.)

Product:
World of Warcraft

Version:
6.1.2.19865

MD5:
efd2bdb69a604ed1cbe9a19fd437395f

SHA-1:
0b56ddb7cddff6574ba61640fd620bf7ddc6a435

SHA-256:
0b0ccf6df1baa56a3539b607bf08d22a4b2a585a6a0b8a8c21422396c1768a8a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/2/2024 6:20:58 AM UTC  (today)

File size:
13.6 MB (14,236,208 bytes)

Product version:
Version 6.1.2

Copyright:
Copyright © 2004

Original file name:
WoW.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Authority:
Thawte, Inc.

Valid from:
12/3/2013 1:00:00 AM

Valid to:
12/5/2015 12:59:59 AM

Subject:
CN="Blizzard Entertainment, Inc.", OU=TECHNICAL SUPPORT, O="Blizzard Entertainment, Inc.", L=Irvine, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
54A1AA6802EAD5F58A6A016D4D84C565

File PE Metadata
Compilation timestamp:
4/4/2015 4:16:35 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:M/qx3Pzm9PCr/s1Kxy6MydYWBPpctzFhjHEqGnBWXAhtWkjLc/WyvA58T5rZWuEW:gvgxDzv8CBWXMLovn58tt4ElCYFrT4

Entry address:
0x10C1B

Entry point:
56, 8B, 35, 2C, E5, D9, 00, 6A, 06, FF, D6, 85, C0, 74, 0E, 6A, 0A, FF, D6, 85, C0, 74, 06, 5E, E9, 25, 72, 65, 00, E8, EF, 6F, 65, 00, E8, 2E, 7C, 1A, 00, 50, 68, 97, 9F, DB, 00, BE, 96, 00, 10, 85, 56, E8, 06, 6C, FF, FF, 83, C4, 0C, 56, FF, 15, 30, E5, D9, 00, CC, 55, 8B, EC, 81, EC, 08, 01, 00, 00, 53, 56, 57, BE, 04, 01, 00, 00, 8D, 85, F8, FE, FF, FF, 56, 50, E8, 21, C2, 0D, 00, 8D, 85, F8, FE, FF, FF, 50, E8, F7, C3, 0D, 00, 83, C4, 0C, 33, DB, 88, 18, 8D, 85, F8, FE, FF, FF, BF, F0, 4E, DA, 00, 4E...
 
[+]

Code size:
9.6 MB (10,079,744 bytes)

The file wow_patched.exe has been seen being distributed by the following URL.

Scan wow_patched.exe - Powered by Reason Core Security