ep0000290897.exe

NVIDIA Guard Service

Sony Corporation

This is a setup program which is used to install the application. The file has been seen being downloaded from download.sony-asia.com.edgesuite.net and multiple other hosts.
Publisher:
Sony Corporation  (signed and verified)

Product:
NVIDIA Guard Service

Version:
2.3.0.06210

MD5:
ad4b643ae3dcae67d5e36a0b6cb22362

SHA-1:
3e753f3d0175d8efd187b3101601c5498057e786

SHA-256:
9d56c00383f58d4d6fa8ed275dd30f5be2e4872e37f7392630f407c2121f8b52

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/25/2024 9:47:06 PM UTC  (today)

File size:
4.2 MB (4,429,752 bytes)

Product version:
1.3.0.0

Copyright:
©2013 Sony Corporation

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ep0000290897.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/6/2012 2:00:00 AM

Valid to:
3/7/2013 1:59:59 AM

Subject:
CN=Sony Corporation, OU=VAIO & Mobile Business Group VAIO Common Engineering Div., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sony Corporation, L=Minato-ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
420D0C00EDE8354C71D17C4599D4B830

File PE Metadata
Compilation timestamp:
6/21/2011 10:33:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:P6m2Jb6I3KV56NtWCI1t9Ccz0f2/NrdcxTTBB+aviJmwPPb1:P6m2Jb6I3KV56nIq8CTT3+w/qB

Entry address:
0x2B451

Entry point:
E8, A0, 81, 00, 00, E9, 17, FE, FF, FF, 51, C7, 01, 7C, 99, 44, 00, E8, 23, 82, 00, 00, 59, C3, 56, 8B, F1, E8, EA, FF, FF, FF, F6, 44, 24, 08, 01, 74, 07, 56, E8, 02, 45, FE, FF, 59, 8B, C6, 5E, C2, 04, 00, 8B, 44, 24, 04, 83, C1, 09, 51, 83, C0, 09, 50, E8, 6A, 82, 00, 00, F7, D8, 59, 1B, C0, 59, 40, C2, 04, 00, 3B, 0D, B8, 76, 45, 00, 75, 02, F3, C3, E9, D9, 82, 00, 00, 55, 8B, EC, 83, EC, 20, 56, 33, F6, 39, 75, 0C, 75, 1D, E8, 20, 3B, 00, 00, 56, 56, 56, 56, 56, C7, 00, 16, 00, 00, 00, E8, D7, 14, 00...
 
[+]

Entropy:
7.6406

Code size:
276 KB (282,624 bytes)

The file ep0000290897.exe has been seen being distributed by the following 3 URLs.