WoW.exe

World of Warcraft

Blizzard Entertainment, Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from download1251.mediafire.com.
Publisher:
Blizzard Entertainment  (signed by Blizzard Entertainment, Inc.)

Product:
World of Warcraft

Version:
6.2.3.20779

MD5:
769b1a1693127bce99353c580b07ebcc

SHA-1:
26822b6b5d476063a72564681d247e97def91e8f

SHA-256:
7f82eb016c9807fe8decaba78ddc6ba8ada3dbc5734fcbf2bf1841114af1e0fa

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 3:51:22 AM UTC  (today)

File size:
14 MB (14,649,320 bytes)

Product version:
Version 6.2.3

Copyright:
Copyright © 2004

Original file name:
WoW.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\wow.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/14/2015 1:00:00 AM

Valid to:
1/18/2018 1:00:00 PM

Subject:
CN="Blizzard Entertainment, Inc.", O="Blizzard Entertainment, Inc.", L=Irvine, S=California, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07D9006D6B075E81FC7987596B6B5E56

File PE Metadata
Compilation timestamp:
12/1/2015 10:17:54 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:RHh+eUevQoCY9J+K97tOAy4743vPoZ+8ZPoXW2+cHR2M:3UKQ6Np8Aw3v8oXW2dR2M

Entry address:
0x10459

Entry point:
56, 8B, 35, 10, D5, DE, 00, 6A, 06, FF, D6, 85, C0, 74, 3C, 6A, 0A, FF, D6, 85, C0, 74, 34, E8, E3, ED, 0D, 00, 84, C0, 75, 25, E8, F0, 4A, 6A, 00, E8, 10, 88, 1C, 00, 50, 68, 99, 10, DF, 00, BE, 6B, 00, 10, 85, 56, E8, 3D, 76, FF, FF, 83, C4, 0C, 56, FF, 15, 14, D5, DE, 00, 5E, E9, BE, 4A, 6A, 00, E8, C5, 4A, 6A, 00, E8, E5, 87, 1C, 00, 50, 68, 99, 10, DF, 00, BE, 96, 00, 10, 85, EB, D3, 55, 8B, EC, 81, EC, 08, 01, 00, 00, 53, 56, 57, BE, 04, 01, 00, 00, 8D, 85, F8, FE, FF, FF, 56, 50, E8, 0C, 0A, 0E, 00...
 
[+]

Code size:
9.9 MB (10,401,280 bytes)

The file WoW.exe has been seen being distributed by the following URL.

Scan WoW.exe - Powered by Reason Core Security