InstallWoW.exe

Blizzard InstallWoW

Blizzard Entertainment

This is a setup and installation application. The file has been seen being downloaded from wowaura.com and multiple other hosts.
Publisher:
Blizzard Entertainment  (signed and verified)

Product:
Blizzard InstallWoW

Version:
1, 4, 0, 185

MD5:
f93affbc16f55b8d3c58ef66f2dde7fe

SHA-1:
e5e380a04cf1fb666617ece9a39fd575a28a4608

SHA-256:
bde2b492179c536ea66bb7e082d145638b1d50e704d7a17c357ac02ac3d7c4b2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/12/2025 11:49:16 PM UTC  (a few moments ago)

File size:
1.1 MB (1,131,176 bytes)

Product version:
1, 4, 0, 185

Copyright:
(c) 2007-2008 Blizzard Entertainment Inc.

Original file name:
InstallWoW.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\installwow.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
1/10/2008 9:00:00 PM

Valid to:
1/14/2010 8:59:59 PM

Subject:
CN=Blizzard Entertainment, OU=TECHNICAL SUPPORT, O=Blizzard Entertainment, L=Irvine, S=California, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
18AAF92246B92D249454D16DA899F12E

File PE Metadata
Compilation timestamp:
11/5/2008 11:59:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:rx6/mol8UScFMVbP9/jDENL79MQWMyTaphFoodk:Fat8UXuVbP9//ENL7m/MyTuh5k

Entry address:
0x7134B

Entry point:
E8, EC, AD, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 8B, 7D, 08, 33, C0, 83, C9, FF, F2, AE, 83, C1, 01, F7, D9, 83, EF, 01, 8A, 45, 0C, FD, F2, AE, 83, C7, 01, 38, 07, 74, 04, 33, C0, EB, 02, 8B, C7, FC, 5F, C9, C3, CC, CC, CC, 80, F9, 40, 73, 15, 80, F9, 20, 73, 06, 0F, AD, D0, D3, EA, C3, 8B, C2, 33, D2, 80, E1, 1F, D3, E8, C3, 33, C0, 33, D2, C3, 6A, 10, 68, 48, 69, 4C, 00, E8, 01, 22, 00, 00, 33, C0, 33, DB, 39, 5D, 08, 0F, 95, C0, 3B, C3, 75, 20, E8, F4...
 
[+]

Code size:
548 KB (561,152 bytes)

The file InstallWoW.exe has been seen being distributed by the following 2 URLs.

Scan InstallWoW.exe - Powered by Reason Core Security