elevator.exe

Adobe Systems, Incorporated

Publisher:
Adobe Systems, Incorporated  (signed and verified)

MD5:
9790699e527c78cdb8428627c1efdaa9

SHA-1:
b4bcc5b81ef783630671af6be81cfc9a30d6f888

SHA-256:
0eb6ead7158c88936cf222d03fbbddb5302bf95822c5e6551f7783939e18c784

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:57:31 AM UTC  (today)

File size:
45.4 KB (46,496 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\adobe\acrobat\9.2\arm\elevator.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/28/2009 8:00:00 AM

Valid to:
11/5/2012 7:59:59 AM

Subject:
CN="Adobe Systems, Incorporated", OU=Acrobat Engineering, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Adobe Systems, Incorporated", L=San Jose, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0290965E913340CDA6634CEF31F7FD07

File PE Metadata
Compilation timestamp:
11/18/2009 3:01:38 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:GE4sxgIxkhauEXSCKRKA/4P4uw7WRR6lNx95KlPiLWUbCZF:GEDWhJH9KW4P4uw7/F5KBiaQC7

Entry address:
0x11BB

Entry point:
E8, FC, 16, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 58, AD, 40, 00, 89, 0D, 54, AD, 40, 00, 89, 15, 50, AD, 40, 00, 89, 1D, 4C, AD, 40, 00, 89, 35, 48, AD, 40, 00, 89, 3D, 44, AD, 40, 00, 66, 8C, 15, 70, AD, 40, 00, 66, 8C, 0D, 64, AD, 40, 00, 66, 8C, 1D, 40, AD, 40, 00, 66, 8C, 05, 3C, AD, 40, 00, 66, 8C, 25, 38, AD, 40, 00, 66, 8C, 2D, 34, AD, 40, 00, 9C, 8F, 05, 68, AD, 40, 00, 8B, 45, 00, A3, 5C, AD, 40, 00, 8B, 45, 04, A3, 60, AD, 40, 00, 8D, 45, 08, A3, 6C, AD, 40...
 
[+]

Entropy:
6.3438

Code size:
25 KB (25,600 bytes)

The file elevator.exe has been seen being distributed by the following URL.