attendcommunicator.exe

Lenvica Computer Solutions Pvt Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Attend Communicator’.
Publisher:
Lenvica Computer Solutions Pvt Ltd  (signed and verified)

MD5:
626c6675231ba107024b59e0c4bb60b4

SHA-1:
337c55f9053d0cc5676fa7fadb1a0d31d8d56353

SHA-256:
2e1f9495f52414a0656ac48438839be8b077f1037400823cf3498587ab63a0c9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/14/2024 2:12:26 AM UTC  (today)

File size:
2 MB (2,132,976 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\attend hrm\bin\attendcommunicator.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/15/2014 3:00:00 AM

Valid to:
1/15/2017 2:59:59 AM

Subject:
CN=Lenvica Computer Solutions Pvt Ltd, O=Lenvica Computer Solutions Pvt Ltd, STREET="#10, Novel Business Center", STREET=BTM 1st Stage, L=Bangalore, S=Karnataka, PostalCode=560068, C=IN

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D082AA9AF6C30354CC52B532AFEA908E

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:yopV9rfq5UorYAHt428PWd2N/R24TSPALTOYAay4QJPoW5QOeSI21yL4/rux3OJn:5FMcC18PJiALTYJI21yGKOJbI4XQxRA

Entry address:
0x1B9CF8

Entry point:
55, 8B, EC, 83, C4, EC, 33, C0, 89, 45, EC, B8, D0, 92, 5B, 00, E8, FF, D7, E4, FF, 33, C0, 55, 68, E4, 9D, 5B, 00, 64, FF, 30, 64, 89, 20, 8B, 0D, A0, 50, 5C, 00, 8B, 09, 8D, 45, EC, BA, F8, 9D, 5B, 00, E8, 8C, B1, E4, FF, 8B, 45, EC, E8, 30, B3, E4, FF, 50, 6A, FF, 6A, 00, E8, EE, D9, E4, FF, A3, A0, AB, 5C, 00, 33, C0, 55, 68, C7, 9D, 5B, 00, 64, FF, 30, 64, 89, 20, 83, 3D, A0, AB, 5C, 00, 00, 74, 47, E8, 1D, DB, E4, FF, 3D, B7, 00, 00, 00, 74, 3B, A1, 3C, 59, 5C, 00, 8B, 00, E8, DE, EC, EA, FF, A1, 3C...
 
[+]

Entropy:
6.6622

Developed / compiled with:
Microsoft Visual C++

Code size:
1.7 MB (1,806,336 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Attend Communicator

Command:
C:\Program Files\attend hrm\bin\attendcommunicator.exe


Scan attendcommunicator.exe - Powered by Reason Core Security