battlelog-web-plugins-1.118.0-retail-prod.exe

EA Digital Illusions CE AB

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from battlelog-cdn.battlefield.com.
Publisher:
EA Digital Illusions CE AB  (signed and verified)

MD5:
b8bb8418a6cf59a7374fea527c4a1594

SHA-1:
63527d408f3048175d3767071a4db89be566fce3

SHA-256:
7288206be8cb8f754126dcfc78872c429289dd75811794f226306e83ed7d8a49

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/24/2024 1:52:01 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
14168

Trend Micro House Call
TROJ_GEN.F47V0728
7.2.100

File size:
3.7 MB (3,870,984 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\battlelog-web-plugins-1.118.0-retail-prod.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/3/2011 1:00:00 AM

Valid to:
5/3/2014 12:59:59 AM

Subject:
CN=EA Digital Illusions CE AB, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=EA Digital Illusions CE AB, L=Stockholm, S=Stockholms Lan, C=SE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
18F4AE46F276CE96CC56AD2377A76344

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:9R6JGShJUub+CmSRVxvU3cGYR8kTG4mY+56WeyvYUuodzK:9RAhJxXVxvlGYRZY6yvFdd+

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9600

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file battlelog-web-plugins-1.118.0-retail-prod.exe has been discovered within the following program.

Origin  by Electronic Arts
Origin (EA Store) is a digital distribution, digital rights management system from Electronic Arts that allows users to purchase games on the internet for PC and mobile platforms, and download them with the Origin client (formerly EA Download Manager).
www.ea.com
24% remove it
 
Powered by Should I Remove It?

The file battlelog-web-plugins-1.118.0-retail-prod.exe has been seen being distributed by the following URL.

Scan battlelog-web-plugins-1.118.0-retail-prod.exe - Powered by Reason Core Security