crypted-outlook-setup-2016-04-26-en-p.exe

Ralf Schwoebel

Publisher:
Ralf Schwoebel  (signed and verified)

MD5:
fe40d5bf58f0db2db0d23271a3cf1966

SHA-1:
1bc9d1ac3c688ceeac58aee554f2410ba8b92225

SHA-256:
13cfa234be22fd9faa92a0bb2211210a741c2055b717c9a2fe2611bcc2ed9ba0

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/24/2024 6:27:44 PM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM19.1.0000.Malware.Gen
1.0.0.1120

Rising Antivirus
Malware.RDM.10!5.10
23.00.65.16502

File size:
3.1 MB (3,226,944 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\crypted-outlook-setup-2016-04-26-en-p.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
2/16/2015 1:00:00 AM

Valid to:
5/18/2016 12:59:59 AM

Subject:
CN=Ralf Schwoebel, OU=Individual Developer, O=No Organization Affiliation, L=Frankfurt, S=Hessen, C=DE

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0C2B5E3A912ADB0D9AFAF8DC9349EA36

File PE Metadata
Compilation timestamp:
4/26/2016 8:00:33 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
49152:X7pcSNqtf/BKUAB/vnI2Y0JNbww2UAtiX/vnI2YPyKVX:X7I7ANmENb3A0mKKVX

Entry address:
0x51A8B

Entry point:
E9, 70, 7E, 01, 00, E9, 25, 52, 01, 00, E9, 46, 16, 04, 00, E9, 81, 4B, 09, 00, E9, 2C, FA, 00, 00, E9, F7, DF, 05, 00, E9, 12, 52, 01, 00, E9, 4D, 6D, 06, 00, E9, 18, 05, 06, 00, E9, 03, D0, 03, 00, E9, 1E, B8, 00, 00, E9, 69, 72, 00, 00, E9, 24, FB, 05, 00, E9, 7F, C4, 06, 00, E9, EA, C8, 07, 00, E9, F5, A1, 03, 00, E9, E0, 76, 03, 00, E9, 0B, 45, 07, 00, E9, C6, 44, 07, 00, E9, 61, F8, 02, 00, E9, DC, 6D, 01, 00, E9, 47, 05, 01, 00, E9, 52, D0, 07, 00, E9, CD, 44, 07, 00, E9, B8, 03, 06, 00, E9, 63, 51...
 
[+]

Entropy:
6.3106

Developed / compiled with:
Microsoft Visual C++ 8.0 (Debug)

Code size:
684 KB (700,416 bytes)

Scan crypted-outlook-setup-2016-04-26-en-p.exe - Powered by Reason Core Security