HeimdalAgent.exe

Heimdal Agent

CSIS Security Group A/S

Publisher:
CSIS Security Group  (signed by CSIS Security Group A/S)

Product:
Heimdal Agent

Description:
HeimdalAgent

Version:
1.0.3.0

MD5:
e5a2fabdc4cebf8d1f97b9eb8b2d0081

SHA-1:
211c7651ac39b7bde5e1685c918deba3f4d4209e

SHA-256:
6e899b40e855dc04b378142a2f53238ffc9a5f856bb11b40702215918393bdd3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 3:29:10 PM UTC  (today)

File size:
929.2 KB (951,488 bytes)

Product version:
1.0.3.0

Copyright:
Copyright© CSIS Security Group 2010

Original file name:
HeimdalAgent.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\{8093f797-cfa5-4f18-a6ec-111205d6a922}\offline\7d3b53e6\5c84dfd2\heimdalagent.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/9/2009 2:00:00 AM

Valid to:
6/10/2011 1:59:59 AM

Subject:
CN=CSIS Security Group A/S, OU=Secure Application Development, O=CSIS Security Group A/S, L=COPENHAGEN, S=NO, C=DK

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
702C4294A0B08A3D70856205E7FF1C42

File PE Metadata
Compilation timestamp:
10/21/2010 5:19:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:9NiKcqPhbMcPdo3C8kVL6Rw0UvJhu4NHqVSe4SUWndpBEQPhu4NLA8rjPR0mmYoo:9VciOSe4SUh2cWROYovbypwq0El40e6

Entry address:
0x28514

Entry point:
FF, 25, 04, 85, 42, 00, 00, 00, 5F, 43, 6F, 72, 45, 78, 65, 4D, 61, 69, 6E, 00, 6D, 73, 63, 6F, 72, 65, 65, 2E, 64, 6C, 6C, 00, B4, 00, 00, 00, CE, CA, EF, BE, 01, 00, 00, 00, 91, 00, 00, 00, 6C, 53, 79, 73, 74, 65, 6D, 2E, 52, 65, 73, 6F, 75, 72, 63, 65, 73, 2E, 52, 65, 73, 6F, 75, 72, 63, 65, 52, 65, 61, 64, 65, 72, 2C, 20, 6D, 73, 63, 6F, 72, 6C, 69, 62, 2C, 20, 56, 65, 72, 73, 69, 6F, 6E, 3D, 32, 2E, 30, 2E, 30, 2E, 30, 2C, 20, 43, 75, 6C, 74, 75, 72, 65, 3D, 6E, 65, 75, 74, 72, 61, 6C, 2C, 20, 50, 75...
 
[+]

Code size:
892 KB (913,408 bytes)

Scan HeimdalAgent.exe - Powered by Reason Core Security