{blocked}.exe

LastPass Installer

LastPass (Marvasol Inc)

This is a self-extracting archive and installer. This file is installed with multiple programs including LastPass (vain poisto) and LastPass (Endast avinstallera). The file has been seen being downloaded from lastpass.com and multiple other hosts.
Publisher:
LastPass  (signed by LastPass (Marvasol Inc))

Product:
LastPass Installer

Version:
3.1.95

MD5:
e2d8a5375bda1294587d3f7f637bdfae

SHA-1:
0856d653ece91b5ec2ec8e18761b903e901f6912

SHA-256:
93af7356f047bd3d01447111fd755a5579fff0c06cd460d8c276b9033e4a478f

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/23/2024 1:39:46 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.6979

File size:
16 MB (16,790,552 bytes)

Product version:
3.1.95

Copyright:
Copyright 2008-2015

Original file name:
lastpass.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/29/2014 7:00:00 PM

Valid to:
10/29/2017 6:59:59 PM

Subject:
CN=LastPass (Marvasol Inc), O=LastPass (Marvasol Inc), STREET=8315 Lee Highway STE 501, L=Fairfax, S=VA, PostalCode=22031, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CE508B3599B7C4FD38609B65E4DAC72A

File PE Metadata
Compilation timestamp:
7/28/2015 2:33:39 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
393216:gd8Dk9aY4FFJa9O9OxfElah2LNcBcdXjYqWDnDiZtGoSs:0H9af3E9O9i8la6cBcyDnuEs

Entry address:
0x6DE31B0

Entry point:
60, BE, 00, A0, 20, 06, 8D, BE, 00, 70, 1F, FA, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, F8, 15, DE, 06, 57, 83, C3, 04, 53, 68, 9F, 91, FD, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.9984  (probably packed)

Code size:
15.9 MB (16,621,568 bytes)

The file {blocked}.exe has been discovered within the following programs.

lastpass.com
About 1% of users remove it
About 9% of users remove it
LastPass (vain poisto)  by LastPass
About 9% of users remove it
 
Powered by Should I Remove It?

The file {blocked}.exe has been seen being distributed by the following 13 URLs.

https://lastpass.com/.../?lang=he

https://lastpass.com/.../

Scan {blocked}.exe - Powered by Reason Core Security