f79ccccae991ab6e021256f4f7365901d7d352c6ff27ebff4334f5c0adb92c32_87636760

Plex Media Server

Plex, Inc.

Publisher:
Plex, Inc.  (signed and verified)

Product:
Plex Media Server

Version:
0.9.1406

MD5:
ddcec0cde95dc884dede7660a1250921

SHA-1:
6b80f93c6b54475632693607f0cdf06f7b97ce55

SHA-256:
6f2a24b5864ed9f7ef17fddec2e79dfd362ec52d992175138ed3e0fbd58a3910

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 12:06:34 AM UTC  (today)

File size:
83.6 MB (87,636,760 bytes)

Product version:
0.9.1406

Copyright:
Copyright 2013, Plex Inc.

Original file name:
pms.exe

Language:
English (United States)

Common path:
C:\windows\temp\f79ccccae991ab6e021256f4f7365901d7d352c6ff27ebff4334f5c0adb92c32_87636760

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
7/9/2013 8:00:00 PM

Valid to:
10/5/2016 8:00:00 AM

Subject:
CN="Plex, Inc.", O="Plex, Inc.", L=San Jose, S=California, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0D641618AB2CDA5F9F6B14DDF8710BB3

File PE Metadata
Compilation timestamp:
11/28/2013 9:14:28 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1572864:x7UOFhMCSWrIsaHtaE0VIPI5/KS77gQLanee+nTSlcBvutfPCsFEXEPMXzi/ybj:QCSeIs2tX0VYIH77genwcBvyXmwKzi/2

Entry address:
0x267A5

Entry point:
E8, C9, 39, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, D0, 60, 45, 00, 75, 02, F3, C3, E9, C4, 40, 00, 00, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, 44, 7C, 45, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA, 25, 80, 61, 45, 00, 01, 0F, 82, 79, 41, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B...
 
[+]

Entropy:
7.9990  (probably packed)

Code size:
229.5 KB (235,008 bytes)

The file f79ccccae991ab6e021256f4f7365901d7d352c6ff27ebff4334f5c0adb92c32_87636760 has been seen being distributed by the following 7 URLs.

http://www.ranchsendgift.com/k m2pIW ALKDGa7A8mm6gadM11KhHUcJdYI5oj69SE8OSHFYGic0cYQA0GoWnd59fKuggqSsGqyUDSwzcwP86mf YPX9CUoX7NZWEY5v8LmDi3zbQz8n McawN WgpINaCOCVI_J_vkt93d1DSRzgR cXkMPfvEiLPZcX2XOHk9DOjOSeUO5MA1ypzvNpX2D7qYJyIz7fx wsV pNnZU5ZATKr4iQA==-G3IAAMTaZkx3_6ooliAIYiiDh4UxhD1Dndz8Z7rS6VJCCeYYYLAxhuM2xNfc7vsSKR0f92OH_ssueI30W5SNIbMwlKgwvWrMSYaLjkkINevFmrRj

http://www.ranchsendgift.com/LxJPKGc3AUJfko4bNanB_FxYLAzF0BzW4DU33BJNeKI0SmaaNK7Nqe1Hvc2p1w4EKMSxKJCA6efIPooV56uUMDXqXPq9rDtaQUh9ARzFZLc7u8 lppCDsDerPWNfdZPyLeIuYkl1JAtAUkbRRPiRFER7JiqIp4dVahqQvy hxfPK8wMBCaP7M8TfOElFbgwufmYJJIgSgZvgofA4BTdvZTWJLkRcRg==-G3IAAMTaZkx3_6ooliAIYiiDh4UxhD1Dndz8Z7rS6VJCCeYYYLAxhuM2xNfc7vsSKR0f92OH_ssueI30W5SNIbMwlKgwvWrMSYaLjkkINevFmrRj

http://www.ranchsendgift.com/gAH3CYkhsHxt0VPVVPIy8TO _c2Eq19KjBDzZ_mGMzuSTe66e6xUffsBUPxH6VombeBOUmSdLdK5TbpD0ZIRp_wa9zgD2GETTwsXZ1I_niUxABddBTMFWKUR1HOBNb4ciy9ZjN4uv00w0vVtkWhpuJH7S5PgOWV H_68xolLLsCc9MnxJVKl496x3oAdMuRAuUW_FRYKDVv8ENQlQ28sFtx7X_fzFg==-G3IAAMTaZkx3_6ooliAIYiiDh4UxhD1Dndz8Z7rS6VJCCeYYYLAxhuM2xNfc7vsSKR0f92OH_ssueI30W5SNIbMwlKgwvWrMSYaLjkkINevFmrRj