antwordprofiler.exe

AntWordProfiler

Laurence Anthony

This is a setup program which is used to install the application. The file has been seen being downloaded from www.laurenceanthony.net.
Publisher:
Laurence Anthony

Product:
AntWordProfiler

Description:
A freeware vocabulary profiler

Version:
1.4.0.0

MD5:
726964575f597c3bd202fbded05091d4

SHA-1:
8ae436d14f9e68fe3f3911b32b1d4f504470d46d

SHA-256:
1c6347b3f2b329d396a94f32fbd5e27a46627292e7741490e14b55f6d182cf1a

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
1/10/2025 9:14:35 AM UTC  (today)

Scan engine
Detection
Engine version

NANO AntiVirus
Trojan.Win32.Gauss2.cxlcjd
0.30.0.64448

Zillya! Antivirus
Trojan.Gauss2.Win32.1
2.0.0.2016

File size:
10.4 MB (10,866,784 bytes)

Product version:
1.4.0.0

Copyright:
2013

Original file name:
AntWordProfiler

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
12/9/2011 11:00:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:F8e1tnQmnDKPg0CwR913saopsrjphwsTB4h/y7QcdPXqIHhZqO5q8E:+qnQmDv0d13satj7O/+qifql

Entry address:
0x8CCA

Entry point:
55, 8B, EC, 6A, FF, 68, D0, D1, 40, 00, 68, 02, 8E, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 20, 53, 56, 57, 89, 65, E8, 83, 65, FC, 00, 6A, 01, FF, 15, B8, C1, 40, 00, 59, 83, 0D, 58, F8, 40, 00, FF, 83, 0D, 5C, F8, 40, 00, FF, FF, 15, B4, C1, 40, 00, 8B, 0D, B4, F7, 40, 00, 89, 08, FF, 15, B0, C1, 40, 00, 8B, 0D, B0, F7, 40, 00, 89, 08, A1, AC, C1, 40, 00, 8B, 00, A3, 54, F8, 40, 00, E8, C9, 00, 00, 00, 83, 3D, 90, E2, 40, 00, 00, 75, 0C, 68, FE, 8D, 40, 00, FF, 15, A8, C1...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
44 KB (45,056 bytes)

The file antwordprofiler.exe has been seen being distributed by the following URL.

Scan antwordprofiler.exe - Powered by Reason Core Security