hdclone.3.9.5.fe.pl._5fantastic.pl_.exe

SAT Launcher

Miray Software AG

This is a setup and installation application. The file has been seen being downloaded from free3.5fantastic.pl.
Publisher:
Miray Software AG  (signed and verified)

Product:
SAT Launcher

Description:
SAT Application and Installation Launcher

Version:
20100421-2.13.1

MD5:
4758727804e44d47b5ecfadfa243ae89

SHA-1:
46ddd10b0321b32999cbc4e4d609859ed3df37cc

SHA-256:
3329102d07bf8490ff7bbe0809f6706551ab9e56999d719a59d253c1031fdf41

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/6/2024 3:40:00 AM UTC  (today)

File size:
12.8 MB (13,443,792 bytes)

Product version:
2.13.1

Copyright:
Miray Software AG

Original file name:
Choice.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\hdclone.3.9.5.fe.pl._5fantastic.pl_.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/15/2010 6:32:10 PM

Valid to:
3/16/2011 6:32:05 PM

Subject:
CN=Miray Software AG, O=Miray Software AG, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012762FDCE56

File PE Metadata
Compilation timestamp:
10/11/2010 2:50:50 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:P3vvrXGiC1AIt1lqCvpkZuetK4IlXYYB7ZCv7vrXGiC1AIt1lqCvpy:P3vvLGXtHq6kQD4Isv7vLGXtHq6y

Entry address:
0x205A0

Entry point:
E8, 5F, 60, 00, 00, E9, 17, FE, FF, FF, 6A, 0C, 68, 38, E0, 44, 00, E8, 9E, 10, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, 1C, 05, 46, 00, 03, 75, 43, 6A, 04, E8, C0, 62, 00, 00, 59, 83, 65, FC, 00, 56, E8, 2E, 63, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, 4A, 63, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, AE, 61, 00, 00, 59, C3, 56, 6A, 00, FF, 35, 44, CE, 45, 00, FF, 15, EC, 61, 44, 00, 85, C0, 75, 16, E8, B2, 60, 00...
 
[+]

Code size:
276 KB (282,624 bytes)

The file hdclone.3.9.5.fe.pl._5fantastic.pl_.exe has been seen being distributed by the following URL.

Scan hdclone.3.9.5.fe.pl._5fantastic.pl_.exe - Powered by Reason Core Security