webproxy.exe

WebProxy.exe

Threattrack Security, Inc.

It runs as a separate (within the context of its own process) windows Service named “WebProxy”.
Publisher:
ThreatTrack Security Inc.  (signed by Threattrack Security, Inc.)

Product:
WebProxy.exe

Version:
2.3.3.8

MD5:
09b17425af25eb3e0006317be15ee824

SHA-1:
f722657b989042b0366e1fdbb29a52091eb106ea

SHA-256:
e2715d4ec5e7286d88356fd7e6beec0c24a39174e28b2c79534cbc1c8b564301

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 3:57:22 PM UTC  (today)

File size:
6 MB (6,339,200 bytes)

Product version:
2.3.3.8

Copyright:
Copyright © 2010

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\vipre\webproxy.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/6/2015 8:00:00 PM

Valid to:
8/24/2017 8:00:00 AM

Subject:
CN="Threattrack Security, Inc.", O="Threattrack Security, Inc.", L=CLEARWATER, S=FL, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
083B5283A9B6FE6464743383083AB153

File PE Metadata
Compilation timestamp:
5/27/2015 12:01:57 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:NTOfG8sp5HlQsX3vg70sF7hkdTGFWwL6LPNK+uY1nmyjdu7hY8P6MuchCFM1gNTM:NCUYpaPNyfryM5Djx0Y

Entry address:
0x259A04

Entry point:
48, 83, EC, 28, E8, 87, 5B, 01, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 4C, 8B, DC, 49, 89, 5B, 08, 49, 89, 6B, 18, 49, 89, 73, 20, 49, 89, 53, 10, 57, 41, 54, 41, 55, 41, 56, 41, 57, 48, 83, EC, 40, 4D, 8B, 79, 08, 4D, 8B, 31, 8B, 41, 04, 49, 8B, 79, 38, 4D, 2B, F7, 4D, 8B, E1, 4C, 8B, EA, 48, 8B, E9, A8, 66, 0F, 85, ED, 00, 00, 00, 49, 63, 71, 48, 49, 89, 4B, C8, 4D, 89, 43, D0, 48, 8B, C6, 3B, 37, 0F, 83, 81, 01, 00, 00, 48, 03, C0, 48, 8D, 5C, C7, 0C, 8B, 43, F8, 4C, 3B, F0, 0F, 82, A8, 00, 00...
 
[+]

Entropy:
5.6497

Code size:
4.3 MB (4,503,040 bytes)

Service
Display name:
WebProxy

Description:
This service is used to examine web traffic for malicious content

Type:
Win32OwnProcess

Depends on:
RPCSS