eid-diag.exe

eID Diagnostic Tool

Emirates Identity Authority

Publisher:
Logica  (signed by Emirates Identity Authority)

Product:
eID Diagnostic Tool

Version:
1.0.0.1

MD5:
08c14e8d6bd0c5bbbbed4564ebcff87a

SHA-1:
22c478c8f5993f842125387838d223475e4e351d

SHA-256:
6646cbd11ef4c0608941713a4ffe9874b277e18f51b2cc5740b7edd08745424b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 7:49:24 AM UTC  (today)

File size:
1.9 MB (2,016,904 bytes)

Product version:
1.0.0.1

Copyright:
(c) Logica. All rights reserved.

Original file name:
eID-Diag.exe

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\eid-diag.exe.0n7zjeb.partial

Digital Signature
Authority:
Entrust, Inc.

Valid from:
5/16/2012 12:04:03 PM

Valid to:
5/24/2015 9:51:04 PM

Subject:
CN=Emirates Identity Authority, O=Emirates Identity Authority, L=Abu Dhabi, C=AE

Issuer:
CN=Entrust Code Signing Certification Authority - L1D, OU="(c) 2009 Entrust, Inc.", OU=www.entrust.net/rpa is incorporated by reference, O="Entrust, Inc.", C=US

Serial number:
4C171970

File PE Metadata
Compilation timestamp:
12/13/2012 10:39:42 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:G4f0Bj7sm8BX4FVt62k/P8YcPn1te7lhhQFRoPDKLD8S0x6o4r:G4St8BX4Tk/P8YcP1tOlLQFa7GDPNr

Entry address:
0x109540

Entry point:
E8, 5C, D5, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 0C, 75, 1D, E8, 6E, 2D, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 7A, 0D, 00, 00, 83, C4, 14, 83, C8, FF, EB, 4D, 8B, 45, 08, 3B, C3, 74, DC, 56, 89, 45, E8, 89, 45, E0, 8D, 45, 10, 50, 53, FF, 75, 0C, 8D, 45, E0, 50, C7, 45, E4, FF, FF, FF, 7F, C7, 45, EC, 42, 00, 00, 00, E8, F7, 88, 00, 00, 83, C4, 10, FF, 4D, E4, 8B, F0, 78, 07, 8B, 45, E0, 88, 18, EB, 0C, 8D, 45, E0, 50, 53, E8, 76, 87, 00, 00, 59...
 
[+]

Entropy:
6.4381

Code size:
1.2 MB (1,277,952 bytes)

The file eid-diag.exe has been seen being distributed by the following 3 URLs.

https://www.google.com/url?hl=en&q=http://.../DownloadAsset.ashx?file=eID-Diag.exe&token=QyjaEr23YEZ2BklgFN3u7jXF0wK9OUayKZNsKCyzK1s9GhWwTu/B4geJt7VBVv75jn5CKoqROH/jSpl273uGwg==&source=gmail&ust=1476258488916000&usg=AFQjCNGkMhZw-gYIwxatMtP6UCmHuACEtQ

Scan eid-diag.exe - Powered by Reason Core Security