224691-647995-world-of-warcraft.exe

Blizzard InstallWoW

Blizzard Entertainment, Inc.

This is a self-extracting archive and installer. The file has been seen being downloaded from ec.ccm2.net and multiple other hosts.
Publisher:
Blizzard Entertainment  (signed by Blizzard Entertainment, Inc.)

Product:
Blizzard InstallWoW

Version:
1, 4, 0, 371

MD5:
91a5d328f932f456fc0d771da5c1af90

SHA-1:
c8bcb3078a28e796203bd2556c96ec2beecaafaa

SHA-256:
e57bfe405c19afb4b9e3347c4f3b172386590986abe4668990bc44ec809981d8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 7:46:23 AM UTC  (today)

File size:
1.6 MB (1,663,664 bytes)

Product version:
1, 4, 0, 371

Copyright:
(c) 2007-2008 Blizzard Entertainment Inc.

Original file name:
TryWoW.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\224691-647995-world-of-warcraft.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
1/8/2010 1:00:00 AM

Valid to:
12/6/2011 12:59:59 AM

Subject:
CN="Blizzard Entertainment, Inc.", OU=TECHNICAL SUPPORT, O="Blizzard Entertainment, Inc.", L=Irvine, S=California, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
7B715B3347BC57B25C66B34202F4A1A0

File PE Metadata
Compilation timestamp:
2/2/2010 6:37:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:gYxmgLau8NyLJSIwl2GkBRzUAhsMjQzRJWMuTyOW6CI3aW53yoodT:gYMLNMJUl23RzXsMjQVgMuT7W6CwRwT

Entry address:
0x885FB

Entry point:
E8, 1C, AF, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 8B, 7D, 08, 33, C0, 83, C9, FF, F2, AE, 83, C1, 01, F7, D9, 83, EF, 01, 8A, 45, 0C, FD, F2, AE, 83, C7, 01, 38, 07, 74, 04, 33, C0, EB, 02, 8B, C7, FC, 5F, C9, C3, CC, CC, CC, 80, F9, 40, 73, 15, 80, F9, 20, 73, 06, 0F, AD, D0, D3, EA, C3, 8B, C2, 33, D2, 80, E1, 1F, D3, E8, C3, 33, C0, 33, D2, C3, 6A, 10, 68, 38, C1, 4E, 00, E8, 39, 23, 00, 00, 33, C0, 33, DB, 39, 5D, 08, 0F, 95, C0, 3B, C3, 75, 20, E8, F4...
 
[+]

Code size:
644 KB (659,456 bytes)

The file 224691-647995-world-of-warcraft.exe has been seen being distributed by the following 16 URLs.

http://ec.ccm2.net/es.ccm.net/download/.../InstallWoW-4.2.0.14333_.exe

http://download28.mediafire.com/l3i0s64qdxng/.../InstallWoW.exe

http://download16.mediafire.com/fukhy2ga7rmg/.../InstallWoW.exe

http://download871.mediafire.com/rjfzwztvdrug/.../InstallWoW.exe

http://download16.mediafire.com/j0jw6fq8kq5g/.../InstallWoW.exe

http://gsf-cf.softonic.com/c8b/cb3/.../file?channel=WEB_SD&fdh=no&id_file=38943&instance=sd_client_es&type=PROGRAM&Expires=1407491603&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=UTXNT1EC96WIQgAwiId0mJdQ-vEdbSkVCTKaXhh7YeuZclYseWaMFFEB3P68ys1392QNSfeb52qLkZx5NTRmSU8UpG4lJwQdNewwWA-57qv1vxU1OIBaD3KFOjrpJlN50GO018EMYwxSYKNkjkNcgcWUjhrIB06YMu6oJU1aHPw_&filename=InstallWoW.exe

http://download1639.mediafire.com/l2a7h8ha9o3g/.../InstallWoW.exe

http://download675.mediafire.com/dfm1ct3ldddg/.../InstallWoW.exe

Scan 224691-647995-world-of-warcraft.exe - Powered by Reason Core Security