vandenborremysecurity_c-rkvg7-zfdl6-qj3nt-tnpbn_.exe

F-Secure Service Enabler

F-Secure Corporation

This is a setup and installation application. The file has been seen being downloaded from download.sp.f-secure.com and multiple other hosts.
Publisher:
F-Secure Corporation  (signed and verified)

Product:
F-Secure Service Enabler

Description:
F-Secure Network Installer

Version:
3.04.134.0

MD5:
3fc0712faca89433f16f3dbc2771b062

SHA-1:
5afb3a3be085b9474f5421fe75fef16d528563ef

SHA-256:
2ace28e294eb1df7dc9841d20da28651b55e73d454676e7a18e4a405d26eea0e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/13/2025 4:25:44 PM UTC  (today)

File size:
837.5 KB (857,640 bytes)

Product version:
3.04.134.0

Copyright:
Copyright © 2014-2015 F-Secure Corporation

Original file name:
NetworkInstaller.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\vandenborremysecurity_c-rkvg7-zfdl6-qj3nt-tnpbn_.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/27/2013 11:35:49 AM

Valid to:
8/27/2016 11:35:49 AM

Subject:
CN=F-Secure Corporation, O=F-Secure Corporation, L=Helsinki, C=FI

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215C82A2BAAB2F01B7E6766BD948E624F6

File PE Metadata
Compilation timestamp:
5/25/2015 12:04:24 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:OLtxBim1EpUuv5j1zZjTkIEDPdC2gMZ7WpsWnGgUN:OLRiIEpNv9tZjdEDU2bZ7WpdnGBN

Entry address:
0x290D8

Entry point:
E8, E3, 86, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, 7D, 08, 00, 75, 04, 33, C0, 5D, C3, 53, 57, FF, 75, 08, E8, C7, 21, 00, 00, 8D, 78, 01, 57, E8, ED, 01, 00, 00, 8B, D8, 59, 59, 85, DB, 74, 15, FF, 75, 08, 57, 53, E8, 83, 8B, 00, 00, 83, C4, 0C, 85, C0, 75, 0A, 8B, C3, EB, 02, 33, C0, 5F, 5B, 5D, C3, 33, C0, 50, 50, 50, 50, 50, E8, 96, 27, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 0C, 57, 85, C9, 0F, 84, 92, 00, 00, 00, 56, 53, 8B, D9, 8B, 74, 24, 14, F7, C6, 03...
 
[+]

Code size:
270 KB (276,480 bytes)

The file vandenborremysecurity_c-rkvg7-zfdl6-qj3nt-tnpbn_.exe has been seen being distributed by the following 6 URLs.

https://download.sp.f-secure.com/SE/Vandenborre/.../Vanden Borre My Security_C-82NRM-P7YHM-PR2XF-H9XBH_.exe

https://download.sp.f-secure.com/SE/Vandenborre/.../VandenBorreMySecurity_C-MCQYJ-EWRCV-WLPJ6-UH2E7_.exe

https://download.sp.f-secure.com/SE/Vandenborre/.../VandenBorreMySecurity_C-C9B2Z-F3GF6-ZTDLK-DGLVK_.exe