TimeClockWindowDownloader.exe

TimeClockWindow Downloader

ZPAY Payroll Systems, Inc.

The executable TimeClockWindowDownloader.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
ZPAY Payroll Systems, Inc.  (signed and verified)

Product:
TimeClockWindow Downloader

Version:
1.0.0

MD5:
71a0220b2e346e4abf2f8768f633935b

SHA-1:
edaeaf85b826c5bfbd3fc43468bd473f51b7871c

SHA-256:
50cb674a2866c69a3307fd3118317f51be711c511eb19ed04cfc6f27badb0e56

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/28/2024 3:19:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.4.4.0

File size:
992.5 KB (1,016,288 bytes)

Product version:
1.0.0

Copyright:
© ZPAY Payroll Systems, Inc.

Original file name:
TimeClockWindowDownloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\timeclockwindowdownloader.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/20/2015 6:00:00 PM

Valid to:
11/20/2018 5:59:59 PM

Subject:
CN="ZPAY Payroll Systems, Inc.", O="ZPAY Payroll Systems, Inc.", STREET=10745 Serenity Ln, L=Savanna, S=IL, PostalCode=61074, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00831BC12FD5D0F9A948350E856FC77909

File PE Metadata
Compilation timestamp:
5/6/2009 12:38:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:Jx4Mi4+EaWyZDAbKh6tBoJU0DuF4jovaVGMwhJE/zlpswuk:tcEaWjrjiA4jova8Mz/zlpswuk

Entry address:
0x8B902

Entry point:
E8, 2D, 79, 00, 00, E9, 16, FE, FF, FF, 8B, 44, 24, 04, 33, C9, 3B, 04, CD, 90, 46, 4D, 00, 74, 12, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0C, 6A, 0D, 58, C3, 8B, 04, CD, 94, 46, 4D, 00, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, C3, E8, 5E, 3D, 00, 00, 85, C0, 75, 06, B8, F8, 47, 4D, 00, C3, 83, C0, 08, C3, E8, 4B, 3D, 00, 00, 85, C0, 75, 06, B8, FC, 47, 4D, 00, C3, 83, C0, 0C, C3, 56, E8, E7, FF, FF, FF, 8B, 4C, 24, 08, 51, 89, 08, E8, 8D, FF, FF, FF, 59, 8B, F0...
 
[+]

Entropy:
6.4710

Code size:
684 KB (700,416 bytes)

Remove TimeClockWindowDownloader.exe - Powered by Reason Core Security