pspice91xp.virtual.exe

OrCAD Capture

OrCAD, Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from upel.agh.edu.pl and multiple other hosts.
Publisher:
OrCAD, Inc.

Product:
OrCAD® Capture

Description:
Capture

Version:
28

MD5:
7b4c376740773a282913fd296d30f210

SHA-1:
041b876c8c5376c328ddaef4ce0c3d5e6d746730

SHA-256:
5ebaf958cd41b68fdce63d8dca61955ba3053021dfe7216a70b20170e6e40555

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/6/2025 4:22:46 AM UTC  (today)

File size:
21.5 MB (22,593,848 bytes)

Product version:
9.1

Copyright:
Copyright © OrCAD, Inc. 1985-1999

Original file name:
CAPTURE.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
1/18/2013 8:33:10 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:NoUc7z9WNdYRH3c04xi53/hIV/rKXNXkB0v/3UnFH/40Icz5ht1+iF:oEYRHea/E/rKdU0/3SFHNz5/PF

Entry address:
0xA4216

Entry point:
E8, 8D, 70, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 64, EC, 4E, 00, 75, 02, F3, C3, E9, 0F, 71, 00, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 56, 33, F6, 39, 75, 0C, 75, 1D, E8, 16, 5B, 00, 00, 56, 56, 56, 56, 56, C7, 00, 16, 00, 00, 00, E8, 17, 0A, 00, 00, 83, C4, 14, 83, C8, FF, EB, 27, FF, 75, 14, 8D, 45, E0, FF, 75, 10, C7, 45, E4, FF, FF, FF, 7F, FF, 75, 0C, C7, 45, EC, 42, 00, 00, 00, 50, 89, 75, E8, 89, 75, E0, FF, 55, 08, 83, C4, 10, 5E, C9, C3, 8B, FF, 55, 8B, EC, FF, 75, 0C, 6A, 00, FF, 75, 08, 68, FE, B5...
 
[+]

Entropy:
7.9144  (probably packed)

Code size:
781.5 KB (800,256 bytes)

The file pspice91xp.virtual.exe has been seen being distributed by the following 2 URLs.

http://upel.agh.edu.pl/wiet/mod/.../view.php?id=4458

Scan pspice91xp.virtual.exe - Powered by Reason Core Security