symantec-pki-client-plugin-win-x86.exe

Symantec Corporation

This is a setup program which is used to install the application. The file has been seen being downloaded from vip-ssp.verisign.com.
Publisher:
Symantec Corporation  (signed and verified)

MD5:
a8507eefed6fe824d4e879459872d5b3

SHA-1:
04a22bd1e28edc0c190d6bf94e88131a533f5d91

SHA-256:
0a9e446a85357819393a60df58f10d32b01cbb31ec53b2a0ee784a7b4361b598

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 11:29:21 PM UTC  (a few moments ago)

File size:
1.5 MB (1,613,944 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\symantec-pki-client-plugin-win-x86.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/7/2011 7:00:00 PM

Valid to:
3/7/2014 6:59:59 PM

Subject:
CN=Symantec Corporation, OU=BuildGroup, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Symantec Corporation, L=Mountain View, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
44D6274E0B738EE5509F3303FE1C0980

File PE Metadata
Compilation timestamp:
8/9/2011 3:26:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:ccAYAUgR2Aa/+UP9T4QtSF6p2VgYNNMee3uViOnFHMEsXYewKY:cBBUZ/zThw6p2VguNMLcnJpsXY1d

Entry address:
0x2CA2

Entry point:
E8, 96, B6, 00, 00, E9, 78, FE, FF, FF, FF, 35, 08, CE, 57, 00, E8, 70, 9A, 00, 00, 59, 85, C0, 74, 02, FF, D0, 6A, 19, E8, 50, A5, 00, 00, 6A, 01, 6A, 00, E8, 1C, B8, 00, 00, 83, C4, 0C, E9, FD, B6, 00, 00, 8B, FF, 55, 8B, EC, 53, 33, DB, 39, 5D, 08, 75, 04, 33, C0, EB, 41, 56, 57, FF, 75, 08, E8, 9F, 8A, 00, 00, 8B, F0, 46, 56, E8, 80, 00, 00, 00, 8B, F8, 59, 59, 3B, FB, 74, 22, FF, 75, 08, 56, 57, E8, 46, 0E, 00, 00, 83, C4, 0C, 85, C0, 74, 0D, 53, 53, 53, 53, 53, E8, A4, F8, FF, FF, 83, C4, 14, 8B, C7...
 
[+]

Entropy:
7.7400  (probably packed)

Code size:
383.5 KB (392,704 bytes)

The file symantec-pki-client-plugin-win-x86.exe has been seen being distributed by the following URL.