microsoft.practices.composite.dll.deploy

Best Buy Co, Inc.

Publisher:
Best Buy Co, Inc.  (signed and verified)

MD5:
c529c895503f5705b1bb8f3a61dbf8ea

SHA-1:
8670a1abba5925eda19fae3831859c2bfb54dded

SHA-256:
f412ce1353a0c5501dbda1bb068cc57c35b01bde063e8a635078dd47981baf28

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/24/2024 11:33:07 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Hupigon-ONX [Trj]
160503-1

AVG
Win32/Heur
2015.0.4568

File size:
89.7 KB (91,808 bytes)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\offline\217807d8\1ee5c0b2\microsoft.practices.composite.dll.deploy

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/31/2011 5:00:00 PM

Valid to:
7/8/2012 4:59:59 PM

Subject:
CN="Best Buy Co, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=PC Image Release 1.0, O="Best Buy Co, Inc.", L=Richfield, S=Minnesota, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
21EC469028D95BBEEE862E66E1F22313

File PE Metadata
Compilation timestamp:
8/29/2011 5:49:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:Jc1FAnqEAn5YvEKmMYPmUs3osjFKcibtuLeViX7n09OVyDDMCE:Jc1FoqEAnavEKmMpQcibtuSViXD09VE

Entry address:
0x1654E

Entry point:
73, 00, 11, 7E, 80, A0, 28, A4, 3A, 57, 90, 02, 38, A1, 40, 00, 20, 70, 43, A3, 90, 1A, F0, 01, 02, 2B, 49, 02, 06, 10, 40, 17, 21, E1, 6B, 49, 01, 00, 00, D0, 5D, 00, B3, 55, F0, 00, 3F, 30, 00, 21, F0, 00, 68, 70, 00, C6, 55, 30, 00, 11, B0, 00, 5C, 30, 00, 76, 30, 00, AF, 55, 30, 00, EB, 30, 01, B5, C0, 10, A3, 70, 00, 7B, 85, 30, 00, 38, C1, 03, 11, 0A, 6F, 74, 00, 07, C0, 13, 04, 12, 04, 28, 75, 80, 00, 82, 09, 0C, 13, 05, 34, 27, 10, 07, 90, 11, 05, 25, 30, 13, 0B, 39, 1D, 00, 04, 66, 0A, 38, 78, 39...
 
[+]

Entropy:
6.2061

Code size:
81.5 KB (83,456 bytes)

Scan microsoft.practices.composite.dll.deploy - Powered by Reason Core Security