wow-language-pack-dede-downloader.exe

Blizzard Downloader

Blizzard Entertainment

This is a setup program which is used to install the application. The file has been seen being downloaded from download1594.mediafire.com and multiple other hosts.
Publisher:
Blizzard Entertainment  (signed and verified)

Product:
Blizzard Downloader

Version:
1, 8, 2, 408

MD5:
af64bde46702c45105a772e49521c7cf

SHA-1:
a1e222cd1e1140967a73a9bdca75efffed80396f

SHA-256:
136266ebbdeb361601236f945606a28e4c4c6c089a1e758c204e891b16002559

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 8:38:21 PM UTC  (today)

File size:
1.1 MB (1,113,016 bytes)

Product version:
1, 8, 2, 408

Copyright:
(c) 2004-2008 Blizzard Entertainment

Original file name:
BlizzardDownloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\wow-language-pack-dede-downloader.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
1/11/2008 1:00:00 AM

Valid to:
1/15/2010 12:59:59 AM

Subject:
CN=Blizzard Entertainment, OU=TECHNICAL SUPPORT, O=Blizzard Entertainment, L=Irvine, S=California, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
18AAF92246B92D249454D16DA899F12E

File PE Metadata
Compilation timestamp:
6/26/2008 8:48:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:7Z8GTohw/67euyUKtrkeeXQDbekVT78N9syJXon0:7Z8YoTedFkeegDzTYN9RXu0

Entry address:
0x88A7D

Entry point:
E8, E8, C1, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 80, F9, 40, 73, 15, 80, F9, 20, 73, 06, 0F, AD, D0, D3, EA, C3, 8B, C2, 33, D2, 80, E1, 1F, D3, E8, C3, 33, C0, 33, D2, C3, 6A, 10, 68, 98, DB, 4D, 00, E8, C5, 57, 00, 00, 33, C0, 33, DB, 39, 5D, 08, 0F, 95, C0, 3B, C3, 75, 20, E8, FF, 1D, 00, 00, C7, 00, 16, 00, 00, 00, 53, 53, 53, 53, 53, E8, CE, D2, FF, FF, 83, C4, 14, 83, C8, FF, E9, F7, 00, 00, 00, 33, C0, 8B, 75, 0C, 3B, F3, 0F, 95, C0, 3B, C3, 74, D2, F6, 46, 0C, 40, 0F, 85...
 
[+]

Code size:
660 KB (675,840 bytes)

The file wow-language-pack-dede-downloader.exe has been seen being distributed by the following 2 URLs.

http://download1594.mediafire.com/t69zigksq2ug/.../WoW-Language-Pack-deDE-downloader.exe

Scan wow-language-pack-dede-downloader.exe - Powered by Reason Core Security