sbe5_pcfw_en_150511.exe

Sound Blaster E-Series

Creative Technology Ltd

Publisher:
Creative Technology Ltd  (signed and verified)

Product:
Sound Blaster E-Series

Description:
Sound Blaster E5 Firmware Update

Version:
1.1.6881.21988

MD5:
a8ac7633f7e977699465479a32348131

SHA-1:
83b3897e720eb222d20b4b773fca94ff9468b373

SHA-256:
d52a2ef915bc4e33b16f7010b1dbcecd99e3c46109909f34de65747c5d4c3f9e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 1:22:00 PM UTC  (today)

File size:
2.9 MB (3,081,160 bytes)

Product version:
1.1.6881.21988

Copyright:
Copyright (c) 2010-2015 Creative Technology Ltd

Original file name:
U3CFlash.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\sbe5_pcfw_en_150511.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/2/2014 8:00:00 AM

Valid to:
9/7/2016 8:00:00 PM

Subject:
CN=Creative Technology Ltd, O=Creative Technology Ltd, L=Singapore, C=SG

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
09DDC9DE8799721AF895FB31E6992E9F

File PE Metadata
Compilation timestamp:
5/11/2015 2:27:58 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:sJBzKx87R71HI/AyNwM35/azDlF//hp3qvUD51gMh9+sdERkkMOiqbxL4Ap1roJ:sb2mdyNbK/hp3qvoOWb

Entry address:
0x1441D

Entry point:
E8, D1, 8A, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 58, 9F, 43, 00, E8, 09, 0F, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, A4, 30, 44, 00, 03, 75, 43, 6A, 04, E8, D2, 28, 00, 00, 59, 83, 65, FC, 00, 56, E8, FA, 28, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, 1B, 29, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, BE, 27, 00, 00, 59, C3, 56, 6A, 00, FF, 35, 64, 14, 44, 00, FF, 15, C4, 10, 43, 00, 85, C0, 75, 16, E8, D0, 07, 00...
 
[+]

Entropy:
6.0279

Code size:
189.5 KB (194,048 bytes)

The file sbe5_pcfw_en_150511.exe has been seen being distributed by the following URL.