PSafeAVD.exe

PSafe Antivirus Setup Launcher

PSafe Tecnologia S.A.

Publisher:
PSafe Tecnologia  (signed by PSafe Tecnologia S.A.)

Product:
PSafe Antivirus Setup Launcher

Description:
PSafe Tecnologia

Version:
4.1.11402.6101

MD5:
5bcdb945ed9e68dff02eaa40ed9cc76f

SHA-1:
52c9ebd223f408d2256ff14ca8aa197020a64316

SHA-256:
de64096f4c24690bd4211933f476551b452882291d0f76cd86674edbbd396a16

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 9:45:03 AM UTC  (today)

File size:
612.2 KB (626,888 bytes)

Product version:
4.1.11402.6101

Copyright:
Copyright (C) 2014

Original file name:
PSafeAVD.exe

Language:
Espanhol (Espanha - tradicional)

Common path:
C:\users\{user}\appdata\local\temp\79382a8.tmp

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/20/2013 9:00:00 PM

Valid to:
1/26/2015 9:00:00 AM

Subject:
CN=PSafe Tecnologia S.A., O=PSafe Tecnologia S.A., L=Rio de Janeiro, S=Rio de Janeiro, C=BR

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07F79AA9335B794D70779F719061AFF2

File PE Metadata
Compilation timestamp:
2/6/2014 1:37:34 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:8mM+xRvcdWFCpiDap/6mtyclLT3PZakXFm+GqvCv8+ED5av8P:8mMucdWT8yclLoiIJN8+EVavw

Entry address:
0x2F539

Entry point:
E8, 0F, 89, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 68, 1A, 47, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 6C, 1A, 47, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, B1, 6D, 00, 00, 85, C0, 75, 06, B8, D0, 1B, 47, 00, C3, 83, C0, 08, C3, E8, 9E, 6D, 00, 00, 85, C0, 75, 06, B8, D4, 1B, 47, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Code size:
375.5 KB (384,512 bytes)

The file PSafeAVD.exe has been seen being distributed by the following 2 URLs.

http://dl-2.kbm2.com/.../Psafe20140206a.exe

Scan PSafeAVD.exe - Powered by Reason Core Security