Ahnblatt.exe

Ahnenblatt

Dirk Boettcher

This is a setup program which is used to install the application. The file has been seen being downloaded from download.poczta.onet.pl.
Publisher:
Dirk Böttcher  (signed by Dirk Boettcher)

Product:
Ahnenblatt

Version:
2.95.11.1

MD5:
5a9c68f9f5edfad1348a33a28bcf4fae

SHA-1:
c400766446d9ebe164fc89a65495fc53a3e8ef2c

SHA-256:
f331c8d8a665af11ed65337e150048b5562095e563b2c1fc4532e05cd2592fdd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/14/2025 9:38:25 PM UTC  (today)

File size:
8 MB (8,370,304 bytes)

Product version:
2.95a

Copyright:
(C) Dirk Böttcher 1992-2016

Original file name:
Ahnblatt.exe

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\ahnenblatt\ahnblatt.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
2/2/2016 7:27:06 AM

Valid to:
2/1/2018 7:27:06 AM

Subject:
E=dirk.boettcher@ahnenblatt.de, CN=Dirk Boettcher, OU=none, O=Dirk Boettcher, C=DE

Issuer:
CN=Certum Code Signing CA SHA2, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
0A2A26D3D057CA8FFE4A89CF992712E5

File PE Metadata
Compilation timestamp:
6/2/2016 6:58:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
196608:E3uEBU9fedVn0eErbGgrMY/stZ3Rvw1hc6bYEgq1JnHeZG57Sx9kDE9fF7pwBU9n:MuCU92dVn0eErbGgrMY/stZ3Rvw1hc6E

Entry address:
0x1FEC

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, 8C, F0, 8C, 00, A1, 7F, F0, 8C, 00, C1, E0, 02, A3, 83, F0, 8C, 00, 52, 6A, 00, E8, F5, BA, 4C, 00, 8B, D0, E8, 06, 66, 44, 00, 5A, E8, 28, 65, 44, 00, E8, 3B, 66, 44, 00, 6A, 00, E8, 04, 78, 44, 00, 59, 68, 28, F0, 8C, 00, 6A, 00, E8, CF, BA, 4C, 00, A3, 87, F0, 8C, 00, 6A, 00, E9, 97, 14, 45, 00, E9, 36, 78, 44, 00, 33, C0, A0, 71, F0, 8C, 00, C3, A1, 87, F0, 8C, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, 14, 01, 00, 00, 0B, C9...
 
[+]

Code size:
4.8 MB (5,038,080 bytes)

The file Ahnblatt.exe has been seen being distributed by the following URL.

https://download.poczta.onet.pl/51640837/.../Ahnblatt.exe

Scan Ahnblatt.exe - Powered by Reason Core Security