upwork.exe

Upwork Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Upwork’.
Publisher:
Upwork Inc.  (signed and verified)

MD5:
e5cba5e1c4a21b2e66bc9c06af06a42b

SHA-1:
41ee638595cbd499c66349a96afd0c5ac6590762

SHA-256:
0fb919a1d90af4841b4e0f7ccecfef05470f975ec8aac78b129ab18bfcea00fe

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/18/2024 11:20:11 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

File size:
2.2 MB (2,346,191 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\upwork\upwork.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
4/18/2016 6:00:00 AM

Valid to:
5/29/2019 6:00:00 PM

Subject:
CN=Upwork Inc., O=Upwork Inc., L=Mountain View, S=California, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
075281B334A8AEC791A01134E615E504

File PE Metadata
Compilation timestamp:
8/20/2016 12:30:35 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0xFF7FF

Entry point:
E9, E3, 91, F6, FF, E9, 39, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 53, 57, 33, DB, 6A, 07, 33, C0, 59, 8D, 7D, E4, 89, 5D, E0, F3, AB, 39, 45, 10, 75, 15, E8, 40, FD, FF, FF, C7, 00, 16, 00, 00, 00, E8, 83, A2, FF, FF, 83, C8, FF, EB, 75, 8B, 45, 0C, 56, 8B, 75, 08, 85, C0, 74, 19, 85, F6, 75, 15, E8, 1C, FD, FF, FF, C7, 00, 16, 00, 00, 00, E8, 5F, A2, FF, FF, 83, C8, FF, EB, 50, B9, FF, FF, FF, 7F, 89, 4D, E4, 3B, C1, 77, 03, 89, 45, E4, 8D, 45, 14, 50, 53, FF, 75, 10, 8D, 45, E0, 50, C7, 45, EC, 42, 00, 00...
 
[+]

Entropy:
6.7712

Packer / compiler:
Xtreme-Protector v1.05

Code size:
1.2 MB (1,255,424 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Upwork

Command:
C:\Program Files\upwork\upwork.exe


Scan upwork.exe - Powered by Reason Core Security