mtw6.7.exe

MathType 6.7

Design Science Inc.

This is a setup program which is used to install the application. This file is installed with the program MathType 6. The file has been seen being downloaded from doc-04-9s-docs.googleusercontent.com and multiple other hosts.
Publisher:
Design Science, Inc.  (signed by Design Science Inc.)

Product:
MathType 6.7

Description:
MathType for Windows version 6.7

Version:
6.7

MD5:
02190938226e36a688d9ff5bea761d87

SHA-1:
4f35d403639d7da07dca359bb030f06e6ecab259

SHA-256:
de13ae17f29d4e9ecfbff3239410f2846f6f26ed4cff62e8004d666fadf7ae02

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/27/2024 4:54:36 PM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
DOC:Attention.APT-Bait.MaliciousFile/Heur!1.9DC3
23.00.65.14318

File size:
6.1 MB (6,387,536 bytes)

Product version:
6.7

Copyright:
©1990-2010 by Design Science, Inc.

Original file name:
stub32i.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/19/2010 1:00:00 AM

Valid to:
9/2/2012 12:59:59 AM

Subject:
CN=Design Science Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Design Science Inc., L=Long Beach, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7653681CCE279A2BD2D942EF3C9C1E21

File PE Metadata
Compilation timestamp:
3/27/2000 7:09:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:T7tFJxvX6D8VOFSuxSxtmmG6eNXpMkjuAnU9+K5:tFJxvX22bmmG6Cpj7U9+K5

Entry address:
0x83F7

Entry point:
55, 8B, EC, 6A, FF, 68, 10, 23, 41, 00, 68, 30, B5, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, E8, 21, 41, 00, 33, D2, 8A, D4, 89, 15, 30, 53, 41, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 2C, 53, 41, 00, C1, E1, 08, 03, CA, 89, 0D, 28, 53, 41, 00, C1, E8, 10, A3, 24, 53, 41, 00, 33, F6, 56, E8, E0, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, 11, 2F, 00, 00, FF, 15, EC, 21, 41, 00, A3, E4, 68, 41, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
68 KB (69,632 bytes)

The file mtw6.7.exe has been discovered within the following program.

MathType 6  by Design Science, Inc.
Publisher's description - “MathType is a powerful interactive equation editor for Windows and Macintosh that lets you create mathematical notation for word processing, web pages, desktop publishing, presentations, elearning, and for TeX, LaTeX, and MathML documents.”
www.dessci.com
4% remove it
 
Powered by Should I Remove It?

The file mtw6.7.exe has been seen being distributed by the following 7 URLs.

https://doc-04-9s-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/kpeienvrohfrk83kljlnf1h7v2htgtml/1474977600000/00746232746295253351/.../0BwbpVMTw9073cGg4dXpSSUNVd28?e=download

https://doc-0s-0k-docs.googleusercontent.com/docs/securesc/5i9kvg218oi25atcatl7j6un1jqjv7l2/h1c7732q19161n82774na2gio5553k6e/1479405600000/16407024168794230263/.../0B-qA22GFJB8UcWtFMnAxd2s1cFE?h=07251252046026431782&e=download

Scan mtw6.7.exe - Powered by Reason Core Security