installwow.exe

Blizzard InstallWoW

Blizzard Entertainment, Inc.

This is a self-extracting archive and installer. The file has been seen being downloaded from dlw134-2.share-online.biz and multiple other hosts.
Publisher:
Blizzard Entertainment  (signed by Blizzard Entertainment, Inc.)

Product:
Blizzard InstallWoW

Version:
1, 4, 0, 371

MD5:
93f3a6bdd9fe8ef08c98f64395046677

SHA-1:
1e4c40fbc9d01b6bdb9e930dd561f4b00276b670

SHA-256:
1fbd76431141a84f3c8bddf708ee84b84a69890c83a13f4e4d8e7c319ed77317

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 2:05:08 PM UTC  (today)

File size:
1.6 MB (1,663,664 bytes)

Product version:
1, 4, 0, 371

Copyright:
(c) 2007-2008 Blizzard Entertainment Inc.

Original file name:
TryWoW.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\installwow.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
1/8/2010 1:00:00 AM

Valid to:
12/6/2011 12:59:59 AM

Subject:
CN="Blizzard Entertainment, Inc.", OU=TECHNICAL SUPPORT, O="Blizzard Entertainment, Inc.", L=Irvine, S=California, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
7B715B3347BC57B25C66B34202F4A1A0

File PE Metadata
Compilation timestamp:
2/2/2010 6:37:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:QYxmgLau8NyLJSIwl2GkBRzUAhsMjQzRJWMuTyOW6CI3aW53yoodq:QYMLNMJUl23RzXsMjQVgMuT7W6CwRwq

Entry address:
0x885FB

Entry point:
E8, 1C, AF, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 8B, 7D, 08, 33, C0, 83, C9, FF, F2, AE, 83, C1, 01, F7, D9, 83, EF, 01, 8A, 45, 0C, FD, F2, AE, 83, C7, 01, 38, 07, 74, 04, 33, C0, EB, 02, 8B, C7, FC, 5F, C9, C3, CC, CC, CC, 80, F9, 40, 73, 15, 80, F9, 20, 73, 06, 0F, AD, D0, D3, EA, C3, 8B, C2, 33, D2, 80, E1, 1F, D3, E8, C3, 33, C0, 33, D2, C3, 6A, 10, 68, 38, C1, 4E, 00, E8, 39, 23, 00, 00, 33, C0, 33, DB, 39, 5D, 08, 0F, 95, C0, 3B, C3, 75, 20, E8, F4...
 
[+]

Code size:
644 KB (659,456 bytes)

The file installwow.exe has been seen being distributed by the following 9 URLs.

http://dlw134-2.share-online.biz/fl?fr=C7444BE99C3A2EECFC152A959C435DEEC7222CBEF2402C91C0415710943C66EDFCE8299E1A4447C494E3C7EC5616E116584423173F4122EC94E42AEC56C4F9AA9443E7ADEAFADEECAAF778786EE87ED6942515CF3613239A4553C0EC5052F4CBBF6F2C2565FE08EE9401F55224DBE774&q=v4

https://mega.nz/temporary/.../HtRlETST

https://mega.nz/persistent/.../HtRlETST

Scan installwow.exe - Powered by Reason Core Security