gensmartsfailsafeupdate.exe

Underwood Innovations, LLC

Publisher:
Underwood Innovations, LLC  (signed and verified)

Version:
2.1.0.0

MD5:
d66ee2dab4aff09185cac3b0932c7ca2

SHA-1:
940f5b63119e36167b86a2dee2898363effcd36d

SHA-256:
0da298a099c868890226c7b0c89dc8ee023defdb022989b5041ed3dd8b96ceca

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 8:52:36 AM UTC  (today)

File size:
969.3 KB (992,536 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\gensmartsfailsafeupdate.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
7/19/2006 8:00:00 PM

Valid to:
7/30/2007 7:59:59 PM

Subject:
CN="Underwood Innovations, LLC", OU=SECURE APPLICATION DEVELOPMENT, O="Underwood Innovations, LLC", L=Long Grove, S=Illinois, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
7F6F6C4E1781964E7002A3B9A6F12FB1

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:TQscVuLJzEvXaDu+DSWnH3xqdU7HfeZ1kPHzJnT9EchYRuw4DQFu/U3buRKlemZq:Mn649wBXxwHkfzJnREchYRpIrpghvf+N

Entry address:
0xC7948

Entry point:
55, 8B, EC, 83, C4, F0, B8, E8, 72, 4C, 00, E8, 44, ED, F3, FF, A1, 04, B8, 4C, 00, 8B, 00, E8, E0, 96, F9, FF, A1, 04, B8, 4C, 00, 8B, 00, BA, A8, 79, 4C, 00, E8, C7, 92, F9, FF, 8B, 0D, 70, B7, 4C, 00, A1, 04, B8, 4C, 00, 8B, 00, 8B, 15, B0, 29, 4C, 00, E8, CF, 96, F9, FF, A1, 04, B8, 4C, 00, 8B, 00, E8, 43, 97, F9, FF, E8, 9A, C7, F3, FF, 00, 00, FF, FF, FF, FF, 18, 00, 00, 00, 47, 65, 6E, 53, 6D, 61, 72, 74, 73, 20, 55, 70, 64, 61, 74, 65, 20, 4D, 61, 6E, 61, 67, 65, 72, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6908

Developed / compiled with:
Microsoft Visual C++

Code size:
794.5 KB (813,568 bytes)

The file gensmartsfailsafeupdate.exe has been seen being distributed by the following URL.

Scan gensmartsfailsafeupdate.exe - Powered by Reason Core Security