WebInstaller.exe

OSHI Defender

AVEAS, s.r.o.

This is a setup and installation application. The file has been seen being downloaded from www.oshidefender.com.
Publisher:
Aveas Limited  (signed by AVEAS, s.r.o.)

Product:
OSHI Defender

Version:
1.2.142

MD5:
e82af465cdee77e2b34ddc57999f669d

SHA-1:
c2989ae1b58b7117d927b3f06c85dd5cc1acfc3a

SHA-256:
6bd561490256c4c5b49633d63b294c990d033aa0ace40522b6ff5f06d3952e43

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 3:28:31 AM UTC  (today)

File size:
4.6 MB (4,803,568 bytes)

Product version:
1.2.142.f830f1b4592a

Copyright:
Copyright (c) 2013 Aveas Limited. All rights reserved.

Original file name:
WebInstaller.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\webinstaller.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
9/4/2013 3:00:00 AM

Valid to:
10/22/2014 3:00:00 PM

Subject:
CN="AVEAS, s.r.o.", O="AVEAS, s.r.o.", L=Decin, C=CZ

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
01C9196556B1505D46B0E21D71D4E140

File PE Metadata
Compilation timestamp:
3/3/2014 1:18:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:J05kjzrghMNlN7oUwGjAVw+bVfVoSIIlqZDWNmfPtJh04vzrqNs7obIV8:J05kjzrghMNlRo6jL+bVfakqFNntJ64+

Entry address:
0x10011

Entry point:
E8, 30, 58, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, FF, 75, 0C, 6A, 00, FF, 75, 08, 68, CC, 59, 41, 00, E8, 05, 00, 00, 00, 83, C4, 10, 5D, C3, 55, 8B, EC, 83, EC, 20, 57, 6A, 07, 33, D2, 8D, 7D, E4, 59, 33, C0, 89, 55, E0, F3, AB, 5F, 39, 45, 0C, 75, 15, E8, 32, 14, 00, 00, C7, 00, 16, 00, 00, 00, E8, FE, 40, 00, 00, 83, C8, FF, EB, 27, FF, 75, 14, 8D, 45, E0, C7, 45, E4, FF, FF, FF, 7F, FF, 75, 10, C7, 45, EC, 42, 00, 00, 00, FF, 75, 0C, 89, 55, E8, 50, 89, 55, E0, FF, 55, 08, 83, C4, 10, 8B, E5, 5D, C3...
 
[+]

Code size:
134.5 KB (137,728 bytes)

The file WebInstaller.exe has been seen being distributed by the following URL.

Scan WebInstaller.exe - Powered by Reason Core Security