WowBrowserProxy.exe

World of Warcraft

Blizzard Entertainment, Inc.

Publisher:
Blizzard Entertainment  (signed by Blizzard Entertainment, Inc.)

Product:
World of Warcraft

Description:
World of Warcraft: Browser Proxy

Version:
6, 1, 2, 19865

MD5:
cfa66e53b47df37b2ca3003d5f44d920

SHA-1:
9c9d4dda1771c7ac05d893e7d853f2328df3e5ca

SHA-256:
0f4f4810f2f4fe2c1f7f360fb88a48f4826b88e7b95571803ef5580296e4ec88

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/2/2024 3:42:52 AM UTC  (today)

File size:
739 KB (756,784 bytes)

Product version:
Version 6.1

Copyright:
Copyright © 2012 Blizzard Entertainment

Original file name:
WowBrowserProxy.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\world of warcraft public test\utils\wowbrowserproxy.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
12/2/2013 7:00:00 PM

Valid to:
12/4/2015 6:59:59 PM

Subject:
CN="Blizzard Entertainment, Inc.", OU=TECHNICAL SUPPORT, O="Blizzard Entertainment, Inc.", L=Irvine, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
54A1AA6802EAD5F58A6A016D4D84C565

File PE Metadata
Compilation timestamp:
4/3/2015 10:09:30 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:pYwtzgKTBH6VvffKWFQV9B8zbEiCtKAg4tbu:pYKTBCYV9bKCu

Entry address:
0x18197

Entry point:
E8, 48, 68, 00, 00, E9, 89, FE, FF, FF, FF, 35, 84, 06, 48, 00, FF, 15, B0, 19, 40, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, 75, 5A, 00, 00, 6A, 01, 6A, 00, E8, EF, 68, 00, 00, 83, C4, 0C, E9, B4, 68, 00, 00, 8B, FF, 51, C7, 01, FC, D3, 43, 00, E8, B5, 6A, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 03, 0B, 00, 00, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 83, C1, 09, 51, 83, C0, 09, 50, E8, FF, 0C, 00, 00, F7, D8, 59, 1B, C0, 59...
 
[+]

Entropy:
6.2803

Code size:
225.5 KB (230,912 bytes)

The file WowBrowserProxy.exe has been seen being distributed by the following URL.

Scan WowBrowserProxy.exe - Powered by Reason Core Security