netsession_win.exe

Akamai NetSession Client

GeoTrust Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Akamai NetSession Interface’.
Publisher:
Akamai Technologies, Inc.  (signed by GeoTrust Inc.)

Product:
Akamai NetSession Client

Version:
1.9.3.1

MD5:
24b29f47a80be3e1fb553bd5da70c479

SHA-1:
3da59dd0e70804bf529925afa20aeed36e6e27f0

SHA-256:
0aa48b6cab209fed25d05a3dca1b2ee26603975528393c4920cad183e080e18c

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/16/2024 1:41:39 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

File size:
4.5 MB (4,769,663 bytes)

Product version:
1.9.3.1

Copyright:
Copyright (C) 2007 - 2015 Akamai Technologies, Inc.

Original file name:
netsession_win.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\akamai\netsession_win.exe

Digital Signature
Signed by:

Authority:
GeoTrust Inc.

Valid from:
5/20/2002 9:00:00 PM

Valid to:
5/20/2022 9:00:00 PM

Subject:
CN=GeoTrust Global CA, O=GeoTrust Inc., C=US

Issuer:
CN=GeoTrust Global CA, O=GeoTrust Inc., C=US

Serial number:
023456

File PE Metadata
Compilation timestamp:
9/10/2015 12:58:17 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x187C1A

Entry point:
E9, 6D, F0, 08, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8, 9E, AC, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, 80, 69, 85, 00, 74, 12, 8B, 0D, 38, 67, 85, 00, 85, 48, 70, 75, 07, E8, 47, C9, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 40, 66, 85, 00, 74, 16, 8B, 46, 08, 8B, 0D, 38, 67, 85, 00, 85, 48, 70, 75, 08, E8, A6, C1, 00, 00, 89, 46, 04, 8B, 46, 08, F6, 40, 70, 02, 75, 14, 83, 48, 70, 02, C6, 46, 0C, 01, EB, 0A...
 
[+]

Entropy:
6.8824

Packer / compiler:
Xtreme-Protector v1.05

Code size:
2.9 MB (3,040,768 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Akamai NetSession Interface

Command:
"C:\users\{user}\appdata\local\akamai\netsession_win.exe"


Scan netsession_win.exe - Powered by Reason Core Security