tmp5243.exe

Knowhow Cloud

DSG Retail Limited

This is a self-extracting archive and installer. The file has been seen being downloaded from livedrive.us7.list-manage.com and multiple other hosts.
Publisher:
DSG Retail Limited  (signed and verified)

Product:
Knowhow Cloud

Description:
This installer database contains the logic and data required to install Knowhow Cloud.

Version:
3.0.3.51

MD5:
82b7d0bad9566694c1460c6911b10157

SHA-1:
5ab99167ba7dd04d1f38d75d9987fe3c6e47ffd9

SHA-256:
2c896bd3c91cb9acf282629d75ac41e28c5685197afc700114d3ab548620db51

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:42:37 PM UTC  (today)

File size:
10.3 MB (10,752,552 bytes)

Product version:
3.0.3.51

Copyright:
Copyright (C) 2015 DSG Retail Limited

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\temp\tmp5243.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/26/2013 12:45:51 PM

Valid to:
9/26/2016 12:45:51 PM

Subject:
CN=DSG Retail Limited, O=DSG Retail Limited, L=Hemel Hempstead, S=Hertfordshire, C=GB

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121495C263926CD3E019E9B697461E92DB5

File PE Metadata
Compilation timestamp:
3/13/2014 1:33:11 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:542OgA+WKUkjPZPy0h22ssaZbfIyLYx7lXvnXvuF9N2V0wKCy5ShYY8L96wSU:DOgANKUYPZFh22yzIyslXv/uF9NE5yFG

Entry address:
0x3162E

Entry point:
E8, B9, 9F, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 04, 8B, 4C, 24, 08, F7, C2, 03, 00, 00, 00, 75, 3C, 8B, 02, 3A, 01, 75, 2E, 0A, C0, 74, 26, 3A, 61, 01, 75, 25, 0A, E4, 74, 1D, C1, E8, 10, 3A, 41, 02, 75, 19, 0A, C0, 74, 11, 3A, 61, 03, 75, 10, 83, C1, 04, 83, C2, 04, 0A, E4, 75, D2, 8B, FF, 33, C0, C3, 90, 1B, C0, D1, E0, 83, C0, 01, C3, F7, C2, 01, 00, 00, 00, 74, 18, 8A, 02, 83, C2, 01, 3A, 01, 75, E7, 83, C1, 01, 0A, C0, 74, DC, F7, C2, 02, 00, 00, 00, 74, A4, 66, 8B...
 
[+]

Entropy:
7.9010  (probably packed)

Code size:
277 KB (283,648 bytes)

The file tmp5243.exe has been seen being distributed by the following 7 URLs.

http://livedrive.us7.list-manage.com/.../click?u=de36a06ada0c7ddf5fd492a62&id=37d662ef85&e=52106f6103

http://www.myknowhowcloud.com/download

http://livedrive.us7.list-manage.com/.../click?u=de36a06ada0c7ddf5fd492a62&id=fabb30e4d1&e=8c0d92fb2b

http://livedrive.us7.list-manage.com/.../click?u=de36a06ada0c7ddf5fd492a62&id=08ca78ed72&e=859689df89

Scan tmp5243.exe - Powered by Reason Core Security