wordweb8.exe

WordWeb Software

This is a setup program which is used to install the application. The file has been seen being downloaded from filehippo.com and multiple other hosts.
Publisher:
WordWeb Software  (signed and verified)

MD5:
c154375416d08c06ec38ee308eeb753a

SHA-1:
2835e9269fe3798c6f3a3afeecd56642cc06c5d7

SHA-256:
62c325b766af57f89e7c76fcc5d43ddca7717bf0aa8e6799626139c56b41e4ce

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/27/2024 7:53:11 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Packed.Unknown
23513

File size:
21.5 MB (22,566,680 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\wordweb8.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/13/2014 4:00:00 PM

Valid to:
1/14/2019 3:59:59 PM

Subject:
CN=WordWeb Software, O=WordWeb Software, STREET=10 Southdown Avenue, L=Brighton, S=East Sussex, PostalCode=BN1 6EG, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0086D554557358A5015D34BC85A7F0E05D

File PE Metadata
Compilation timestamp:
10/15/2015 8:34:44 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:MfuoPxTwmM1BJcVqfgYOgMW7jwD90gfuOYTt4DkJjrAGjXttXrcSMLbdRRVZ:MG2MrEMDOjWwDagGOYT2DkJHAgZrcVb5

Entry address:
0x1DA6B

Entry point:
E8, 86, 63, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 82, FC, FF, FF, C7, 06, F0, B2, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, F0, B2, 42, 00, E9, 37, FD, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, F0, B2, 42, 00, E8, 24, FD, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 92, CA, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08, 80, 3A, 00, 74, 3F, 8B, 75, 0C, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08...
 
[+]

Entropy:
7.9985  (probably packed)

Code size:
163 KB (166,912 bytes)

The file wordweb8.exe has been seen being distributed by the following 35 URLs.

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://files1.majorgeeks.com/b6e32320fa6bc5a588b90183b95dc028/.../wordweb8.exe

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

&onid=2279&oid=3001-2279_4-10003201&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=education/language&topicbrcrm=&pid=14485633&mfgid=51098&merid=51098&ctype=dm&cval=NONE&devicetype=desktop&pguid=bbf7f4f7d3fe84c4a62f1c46&viewguid=a584yaSuuWYtz7r9IwEKlx7Go2fI8cBTgBcD&destUrl=http://software-files-a.cnet.com/s/software/14/48/56/.../wordweb8.exe

http://filehippo.com/download/file/.../

&onid=2279&oid=3001-2279_4-10003201&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=education/language&topicbrcrm=&pid=14485633&mfgid=51098&merid=51098&ctype=dm&cval=NONE&devicetype=desktop&pguid=52a717d1f9b2878f82492aa4&viewguid=a7WZr58@r7ZckNlA2U9@-1sh3gwh-TGk1mWg&destUrl=http://software-files-a.cnet.com/s/software/14/48/56/.../wordweb8.exe

&onid=2279&oid=3001-2279_4-10003201&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=education/language&topicbrcrm=&pid=14485633&mfgid=51098&merid=51098&ctype=dm&cval=NONE&devicetype=desktop&pguid=4960634e3ddef64d48c14e77&viewguid=aX67wyq-wfzEap-2l6MZcaVRLD7drOPPifhk&destUrl=http://software-files-a.cnet.com/u/.../wordweb8.exe

temp:wordweb8.exe

&onid=2279&oid=3001-2279_4-10003201&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=education/language&topicbrcrm=&pid=14485633&mfgid=51098&merid=51098&ctype=dm&cval=NONE&devicetype=desktop&pguid=2f9e48f14b09a3e5060ad314&viewguid=bBTz0UBsiSP7sYF033wCijDsotZRLvPVszZh&destUrl=http://software-files-a.cnet.com/s/software/14/48/56/.../wordweb8.exe

Latest 30 of 35 download URLs

Scan wordweb8.exe - Powered by Reason Core Security