{blocked}.exe

LastPass Installer

LastPass (Marvasol Inc)

This is a self-extracting archive and installer. This is installed with multiple programs including LastPass (samo za odstranitev) and LastPass (vain poisto). The file has been seen being downloaded from d1jxck0p3rkj0.cloudfront.net and multiple other hosts.
Publisher:
LastPass  (signed by LastPass (Marvasol Inc))

Product:
LastPass Installer

Version:
3.2.40

MD5:
9199b7195fcacd667585efd4e53e742b

SHA-1:
5c442821a541719729481a14accc2ef62a49e254

SHA-256:
e3e798027be372b87c72a7ba2e4695b0b41a96d8886a0cb6cd36eed1bf7c47c3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 10:52:30 PM UTC  (today)

File size:
19.4 MB (20,320,792 bytes)

Product version:
3.2.40

Copyright:
Copyright 2008-2015

Original file name:
lastpass.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\lastpass_x64.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/30/2014 12:00:00 AM

Valid to:
10/29/2017 11:59:59 PM

Subject:
CN=LastPass (Marvasol Inc), O=LastPass (Marvasol Inc), STREET=8315 Lee Highway STE 501, L=Fairfax, S=VA, PostalCode=22031, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CE508B3599B7C4FD38609B65E4DAC72A

File PE Metadata
Compilation timestamp:
10/23/2015 11:25:01 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
393216:5q+JZyuNIG8sxtTgPgtj7pF1P4Pv2Wm4GxcAmYpODwGa+2g:5jEedRzpsOh4GxjWLV

Entry address:
0x6EEE030

Entry point:
60, BE, 00, 70, FB, 05, 8D, BE, 00, A0, 44, FA, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 32, C7, EE, 06, 57, 83, C3, 04, 53, 68, 20, 70, 33, 01, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.9989  (probably packed)

Code size:
19.2 MB (20,152,320 bytes)

The file {blocked}.exe has been discovered within the following programs.

lastpass.com
About 1% of users remove it
About 1% of users remove it
About 9% of users remove it
LastPass (vain poisto)  by LastPass
About 9% of users remove it
 
Powered by Should I Remove It?

The file {blocked}.exe has been seen being distributed by the following 10 URLs.

Scan {blocked}.exe - Powered by Reason Core Security