buli_1.exe

gimas Gesellschaft fuer InformationsManagement und Software mbH

This is a setup program which is used to install the application. The file has been seen being downloaded from msn.appgallery.de.
MD5:
af13000c0a31463bbef9330fbe12aa40

SHA-1:
1ca5253e8825e12f422c450d4cc98e7161e962b0

SHA-256:
18a2f5986e14604e9ae9bd7ee420479ebee348ee16880af45050384c0539a700

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 5:56:28 AM UTC  (today)

File size:
3.3 MB (3,446,704 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\microsoft\apps\buli_1.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/16/2012 1:00:00 AM

Valid to:
4/20/2015 1:59:59 AM

Subject:
CN=gimas Gesellschaft fuer InformationsManagement und Software mbH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=gimas Gesellschaft fuer InformationsManagement und Software mbH, L=Frankfurt am Main, S=Hessen, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
20DF45A2B86BC013036A1AC8589FA91F

File PE Metadata
Compilation timestamp:
5/2/2012 11:41:49 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:sGriJqQxXCypU/tNR7b9k5NNPhaqvKgnHG+reiECs3YhiPm:sgWhxXCFiYiheiEC8D+

Entry address:
0x1EA694

Entry point:
E8, 1F, A0, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, 20, 56, 6E, 00, 75, 02, F3, C3, E9, A6, A0, 00, 00, 8B, FF, 55, 8B, EC, 8B, 45, 14, 56, 85, C0, 74, 41, 83, 7D, 08, 00, 75, 13, E8, 61, 5D, 00, 00, 6A, 16, 5E, 89, 30, E8, 14, A3, 00, 00, 8B, C6, EB, 2A, 83, 7D, 10, 00, 74, E7, 39, 45, 0C, 73, 0E, E8, 43, 5D, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, DE, 50, FF, 75, 10, FF, 75, 08, E8, F8, 04, 00, 00, 83, C4, 0C, 33, C0, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8...
 
[+]

Code size:
2.2 MB (2,260,480 bytes)

The file buli_1.exe has been seen being distributed by the following URL.

Scan buli_1.exe - Powered by Reason Core Security