× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 102b555901653e0f0b822b97a12517ec42dfb3525ccc6fa5c1d63f3a57fcdb64
File name: Dataram_RAMDisk_4_4_0_RC34.msi
Detection ratio: 1 / 57
Analysis date: 2016-04-03 03:51:03 UTC ( 2 years, 2 months ago ) View latest
Antivirus Result Update
Baidu Multi.Threats.InArchive 20160402
Ad-Aware 20160403
AegisLab 20160403
AhnLab-V3 20160402
Alibaba 20160401
ALYac 20160403
Antiy-AVL 20160403
Arcabit 20160403
Avast 20160403
AVG 20160403
Avira (no cloud) 20160402
AVware 20160403
Baidu-International 20160402
BitDefender 20160403
Bkav 20160402
CAT-QuickHeal 20160402
ClamAV 20160402
CMC 20160401
Comodo 20160402
Cyren 20160403
DrWeb 20160403
Emsisoft 20160403
ESET-NOD32 20160402
F-Prot 20160403
F-Secure 20160403
Fortinet 20160402
GData 20160403
Ikarus 20160402
Jiangmin 20160403
K7AntiVirus 20160402
K7GW 20160403
Kaspersky 20160402
Kingsoft 20160403
Malwarebytes 20160403
McAfee 20160403
McAfee-GW-Edition 20160403
Microsoft 20160402
eScan 20160403
NANO-Antivirus 20160403
nProtect 20160401
Panda 20160402
Qihoo-360 20160403
Rising 20160403
Sophos AV 20160403
SUPERAntiSpyware 20160403
Symantec 20160331
Tencent 20160403
TheHacker 20160330
TotalDefense 20160402
TrendMicro 20160403
TrendMicro-HouseCall 20160403
VBA32 20160401
VIPRE 20160403
ViRobot 20160402
Yandex 20160316
Zillya 20160402
Zoner 20160403
The file being studied is a Windows Installer file! These types of files are software components used for the installation, maintenance, and removal of software on modern Microsoft Windows systems.
Authenticode signature block
Signature verification Signed file, verified signature
Signing date 3:43 AM 7/3/2015
Signers
[+] Dataram Corporation
Status This certificate or one of the certificates in the certificate chain is not time valid.
Valid from 1:00 AM 6/10/2015
Valid to 12:59 AM 6/10/2016
Valid usage Code Signing
Algorithm sha1RSA
Thumbrint 82A2267890657B5847D22E678B878652E33D67B3
Serial number 7C E8 D8 C5 DF D9 A8 44 95 4E 78 C1 41 DE 55 18
[+] VeriSign Class 3 Code Signing 2010 CA
Status Valid
Valid from 1:00 AM 2/8/2010
Valid to 12:59 AM 2/8/2020
Valid usage Client Auth, Code Signing
Algorithm sha1RSA
Thumbrint 495847A93187CFB8C71F840CB7B41497AD95C64F
Serial number 52 00 E5 AA 25 56 FC 1A 86 ED 96 C9 D4 4B 33 C7
[+] VeriSign
Status Valid
Valid from 1:00 AM 11/8/2006
Valid to 12:59 AM 7/17/2036
Valid usage Server Auth, Client Auth, Email Protection, Code Signing
Algorithm sha1RSA
Thumbrint 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
Serial number 18 DA D1 9E 26 7D E8 BB 4A 21 58 CD CC 6B 3B 4A
Counter signers
[+] Symantec Time Stamping Services Signer - G4
Status Valid
Valid from 1:00 AM 10/18/2012
Valid to 12:59 AM 12/30/2020
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 65439929B67973EB192D6FF243E6767ADF0834E4
Serial number 0E CF F4 38 C8 FE BF 35 6E 04 D8 6A 98 1B 1A 50
[+] Symantec Time Stamping Services CA - G2
Status Valid
Valid from 1:00 AM 12/21/2012
Valid to 12:59 AM 12/31/2020
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 6C07453FFDDA08B83707C09B82FB3D15F35336B1
Serial number 7E 93 EB FB 7C C6 4E 59 EA 4B 9A 77 D4 06 FC 3B
[+] Thawte Timestamping CA
Status Valid
Valid from 1:00 AM 1/1/1997
Valid to 12:59 AM 1/1/2021
Valid usage Timestamp Signing
Algorithm md5RSA
Thumbrint BE36A4562FB2EE05DBB3D32323ADF445084ED656
Serial number 00
OLE structured storage summary
creation_datetime
2015-07-03 03:42:52
author
Dataram, Inc.
title
Installation Database
page_count
200
word_count
2
keywords
Windows RAM Disk
last_saved
2015-07-03 03:42:52
revision_number
{D2870978-43BF-4F07-A546-DCFB3A4FCC3B}
application_name
Windows Installer XML (3.7.1224.0)
security
2
subject
Windows RAMDisk Software
template
Intel;1033
code_page
Latin I
comments
RAMDisk is a Windows utility that emulates the functionality of a hard disk using system RAM.
OLE Streams
name
Root Entry
clsid
000c1084-0000-0000-c000-000000000046
type_literal
root
clsid_literal
on
sid
0
size
18368
type_literal
stream
sid
53
name
\x05DigitalSignature
size
6399
type_literal
stream
sid
52
name
\x05MsiDigitalSignatureEx
size
20
type_literal
stream
sid
2
name
\x05SummaryInformation
size
560
type_literal
stream
sid
1
name
\u4126\u3865\u41be\u4164
size
5820302
type_literal
stream
sid
32
name
\u4192\u4472\u3efe\u3d8a\u430d\u43b6\u433e\u44a6
size
312558
type_literal
stream
sid
17
name
\u430b\u4131\u4735\u403e\u46ec\u3a8c
size
156160
type_literal
stream
sid
11
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3aff\u44f0\u3aff\u4464\u4231\u4835
size
114430
type_literal
stream
sid
12
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3aff\u44f0\u3b7f\u412c\u44af\u482a
size
615318
type_literal
stream
sid
15
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3aff\u44f0\u3dff\u46a8
size
318
type_literal
stream
sid
16
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3aff\u44f0\u3fbf\u4833
size
318
type_literal
stream
sid
13
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3cbf\u44a6\u3bbf\u41bb\u412f\u4830
size
766
type_literal
stream
sid
14
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3cbf\u44a6\u3cbf\u4271\u4832
size
1078
type_literal
stream
sid
10
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u4320\u41bb\u4824
size
62464
type_literal
stream
sid
49
name
\u4840\u3b3f\u43f2\u4438\u45b1
size
1560
type_literal
stream
sid
46
name
\u4840\u3c9e\u421d\u45fb
size
204
type_literal
stream
sid
51
name
\u4840\u3f3f\u4577\u446c\u3b6a\u45e4\u4824
size
100327
type_literal
stream
sid
50
name
\u4840\u3f3f\u4577\u446c\u3e6a\u44b2\u482f
size
5580
type_literal
stream
sid
48
name
\u4840\u3f7f\u4164\u422f\u4836
size
76
type_literal
stream
sid
3
name
\u4840\u3fff\u43e4\u41ec\u45e4\u44ac\u4831
size
4728
type_literal
stream
sid
35
name
\u4840\u4115\u4478\u42e6\u448c\u41f1\u45ec\u44ac\u4831
size
4
type_literal
stream
sid
40
name
\u4840\u411b\u4327\u3af2\u45f8\u44b7\u4831
size
72
type_literal
stream
sid
4
name
\u4840\u418a\u4337\u4472\u421d\u45fb
size
18
type_literal
stream
sid
31
name
\u4840\u4192\u4472
size
4
type_literal
stream
sid
5
name
\u4840\u41ca\u4330\u3bb1\u423b\u4626\u4237\u421c\u4634\u4468\u4226
size
48
type_literal
stream
sid
6
name
\u4840\u41ca\u4330\u3fb1\u3f12\u4528\u4238\u41b1\u4828
size
42
type_literal
stream
sid
7
name
\u4840\u41ca\u45f9\u46ce\u41a8\u45f8\u3f28\u4528\u4238\u41b1\u4828
size
48
type_literal
stream
sid
29
name
\u4840\u420f\u45e4\u4578\u3b28\u4432\u44b3\u4231\u45f1\u4836
size
372
type_literal
stream
sid
28
name
\u4840\u420f\u45e4\u4578\u4828
size
16
type_literal
stream
sid
37
name
\u4840\u4216\u4327\u4824
size
14
type_literal
stream
sid
42
name
\u4840\u421b\u3d6a\u41b2\u45e4\u4572
size
560
type_literal
stream
sid
41
name
\u4840\u421b\u432a\u45f6\u4735
size
804
type_literal
stream
sid
43
name
\u4840\u421b\u44b0\u4239\u430f\u422f
size
150
type_literal
stream
sid
45
name
\u4840\u421d\u45fb\u45dc\u43fc\u4828
size
48
type_literal
stream
sid
18
name
\u4840\u42cc\u41a8\u3aee\u46f2
size
8
type_literal
stream
sid
44
name
\u4840\u42dc\u4572\u41b7\u45f8
size
128
type_literal
stream
sid
9
name
\u4840\u430b\u4131\u4735
size
32
type_literal
stream
sid
26
name
\u4840\u430d\u4235\u45e6\u4572\u483c
size
60
type_literal
stream
sid
25
name
\u4840\u430d\u43e4\u42b2
size
528
type_literal
stream
sid
30
name
\u4840\u430f\u422f
size
540
type_literal
stream
sid
33
name
\u4840\u4452\u45f6\u43e4\u3baf\u423b\u4626\u4237\u421c\u4634\u4468\u4226
size
222
type_literal
stream
sid
34
name
\u4840\u4452\u45f6\u43e4\u3faf\u3f12\u4528\u4238\u41b1\u4828
size
150
type_literal
stream
sid
19
name
\u4840\u448c\u44f0\u4472\u4468\u4837
size
1116
type_literal
stream
sid
21
name
\u4840\u448c\u45f1\u44b5\u3b2f\u4472\u4327\u4337\u4472
size
664
type_literal
stream
sid
22
name
\u4840\u448c\u45f1\u44b5\u3baf\u4239\u45f1
size
2112
type_literal
stream
sid
20
name
\u4840\u448c\u45f1\u44b5\u482f
size
6292
type_literal
stream
sid
36
name
\u4840\u4495\u43a6\u4219\u4435\u45ac\u4336\u4472\u4836
size
24
type_literal
stream
sid
8
name
\u4840\u44ca\u3f33\u4128\u41b5\u482b
size
224
type_literal
stream
sid
47
name
\u4840\u44de\u456a\u41e4\u4828
size
48
type_literal
stream
sid
23
name
\u4840\u454c\u4128\u4237\u448f\u41ef\u4568
size
4
type_literal
stream
sid
39
name
\u4840\u4559\u44f2\u4568\u4737
size
188
type_literal
stream
sid
38
name
\u4840\u4596\u3bec\u43ec\u3c68\u45a4\u482b
size
60
type_literal
stream
sid
24
name
\u4840\u460c\u45f6\u4432\u418a\u4337\u4472
size
156
type_literal
stream
sid
27
name
\u4840\u464e\u4468\u3db7\u44e4\u4333\u42b1
size
56
ExifTool file metadata
MIMEType
image/vnd.fpx

ModifyDate
2015:07:03 02:42:52

Template
Intel;1033

Title
Installation Database

FileType
FPX

Author
Dataram, Inc.

Comments
RAMDisk is a Windows utility that emulates the functionality of a hard disk using system RAM.

CodePage
Windows Latin 1 (Western European)

FileTypeExtension
fpx

Words
2

Keywords
Windows RAM Disk

CreateDate
2015:07:03 02:42:52

Security
Read-only recommended

Software
Windows Installer XML (3.7.1224.0)

Pages
200

RevisionNumber
{D2870978-43BF-4F07-A546-DCFB3A4FCC3B}

Subject
Windows RAMDisk Software

File identification
MD5 d0b8c36b31668848f57e1daed5abd9ce
SHA1 46139ef8ccee0aacd16a281722b6276d72bed64b
SHA256 102b555901653e0f0b822b97a12517ec42dfb3525ccc6fa5c1d63f3a57fcdb64
ssdeep
196608:BWY66y9nOznyR6UjztdqpXZ96MBQuzIF:V+WnlgDQXU

File size 6.9 MB ( 7274496 bytes )
File type Windows Installer
Magic literal
CDF V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Installation Database, Subject: Windows RAMDisk Software, Author: Dataram, Inc., Keywords: Windows RAM Disk, Comments: RAMDisk is a Windows utility that emulates the functionality of a hard disk using system RAM., Template: Intel

TrID Microsoft Windows Installer (89.6%)
Windows Installer Patch (8.7%)
Generic OLE2 / Multistream Compound File (1.5%)
Tags
msi signed

VirusTotal metadata
First submission 2015-07-30 05:14:32 UTC ( 2 years, 10 months ago )
Last submission 2018-05-31 09:46:04 UTC ( 3 weeks, 2 days ago )
File names Dataram_RAMDisk_4_4_0_RC3420170701-15470-1v4i9jq.msi
Dataram_RAMDisk_4_4_0_RC34.msi
Dataram_RAMDisk_4_4_0_RC34.sae.msi
182d85.msi
Dataram_RAMDisk_4_4_0_RC34.msi
1- Dataram_RAMDisk_4_4_0_RC34.msi
Dataram_RAMDisk_4_4_0_RC3e.msi
9db52.msi
Dataram_RAMDisk_4_4_0_RC34.msi
e3dc68a.msi
Dataram_RAMDisk_4_4_0_RC34.msi
Dataram_RAMDisk_4_4_0.msi
dataram_ramdisk_4_4_0_rc34.msi
Dataram_RAMDisk_4_4_0_RC34.msi
filename
5d599.msi
22f03c5.msi
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!