× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 102b555901653e0f0b822b97a12517ec42dfb3525ccc6fa5c1d63f3a57fcdb64
File name: Dataram_RAMDisk_4_4_0_RC34.msi
Detection ratio: 1 / 57
Analysis date: 2016-04-03 03:51:03 UTC ( 1 year, 9 months ago ) View latest
Antivirus Result Update
Baidu Multi.Threats.InArchive 20160402
Ad-Aware 20160403
AegisLab 20160403
AhnLab-V3 20160402
Alibaba 20160401
ALYac 20160403
Antiy-AVL 20160403
Arcabit 20160403
Avast 20160403
AVG 20160403
Avira (no cloud) 20160402
AVware 20160403
Baidu-International 20160402
BitDefender 20160403
Bkav 20160402
CAT-QuickHeal 20160402
ClamAV 20160402
CMC 20160401
Comodo 20160402
Cyren 20160403
DrWeb 20160403
Emsisoft 20160403
ESET-NOD32 20160402
F-Prot 20160403
F-Secure 20160403
Fortinet 20160402
GData 20160403
Ikarus 20160402
Jiangmin 20160403
K7AntiVirus 20160402
K7GW 20160403
Kaspersky 20160402
Kingsoft 20160403
Malwarebytes 20160403
McAfee 20160403
McAfee-GW-Edition 20160403
Microsoft 20160402
eScan 20160403
NANO-Antivirus 20160403
nProtect 20160401
Panda 20160402
Qihoo-360 20160403
Rising 20160403
Sophos AV 20160403
SUPERAntiSpyware 20160403
Symantec 20160331
Tencent 20160403
TheHacker 20160330
TotalDefense 20160402
TrendMicro 20160403
TrendMicro-HouseCall 20160403
VBA32 20160401
VIPRE 20160403
ViRobot 20160402
Yandex 20160316
Zillya 20160402
Zoner 20160403
The file being studied is a Windows Installer file! These types of files are software components used for the installation, maintenance, and removal of software on modern Microsoft Windows systems.
Authenticode signature block
Signature verification Signed file, verified signature
Signing date 3:43 AM 7/3/2015
Signers
[+] Dataram Corporation
Status This certificate or one of the certificates in the certificate chain is not time valid.
Valid from 1:00 AM 6/10/2015
Valid to 12:59 AM 6/10/2016
Valid usage Code Signing
Algorithm sha1RSA
Thumbrint 82A2267890657B5847D22E678B878652E33D67B3
Serial number 7C E8 D8 C5 DF D9 A8 44 95 4E 78 C1 41 DE 55 18
[+] VeriSign Class 3 Code Signing 2010 CA
Status Valid
Valid from 1:00 AM 2/8/2010
Valid to 12:59 AM 2/8/2020
Valid usage Client Auth, Code Signing
Algorithm sha1RSA
Thumbrint 495847A93187CFB8C71F840CB7B41497AD95C64F
Serial number 52 00 E5 AA 25 56 FC 1A 86 ED 96 C9 D4 4B 33 C7
[+] VeriSign
Status Valid
Valid from 1:00 AM 11/8/2006
Valid to 12:59 AM 7/17/2036
Valid usage Server Auth, Client Auth, Email Protection, Code Signing
Algorithm sha1RSA
Thumbrint 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
Serial number 18 DA D1 9E 26 7D E8 BB 4A 21 58 CD CC 6B 3B 4A
Counter signers
[+] Symantec Time Stamping Services Signer - G4
Status Valid
Valid from 1:00 AM 10/18/2012
Valid to 12:59 AM 12/30/2020
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 65439929B67973EB192D6FF243E6767ADF0834E4
Serial number 0E CF F4 38 C8 FE BF 35 6E 04 D8 6A 98 1B 1A 50
[+] Symantec Time Stamping Services CA - G2
Status Valid
Valid from 1:00 AM 12/21/2012
Valid to 12:59 AM 12/31/2020
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 6C07453FFDDA08B83707C09B82FB3D15F35336B1
Serial number 7E 93 EB FB 7C C6 4E 59 EA 4B 9A 77 D4 06 FC 3B
[+] Thawte Timestamping CA
Status Valid
Valid from 1:00 AM 1/1/1997
Valid to 12:59 AM 1/1/2021
Valid usage Timestamp Signing
Algorithm md5RSA
Thumbrint BE36A4562FB2EE05DBB3D32323ADF445084ED656
Serial number 00
OLE structured storage summary
creation_datetime
2015-07-03 03:42:52
author
Dataram, Inc.
title
Installation Database
page_count
200
last_saved
2015-07-03 03:42:52
word_count
2
application_name
Windows Installer XML (3.7.1224.0)
comments
RAMDisk is a Windows utility that emulates the functionality of a hard disk using system RAM.
revision_number
{D2870978-43BF-4F07-A546-DCFB3A4FCC3B}
keywords
Windows RAM Disk
security
2
subject
Windows RAMDisk Software
code_page
Latin I
template
Intel;1033
OLE Streams
name
Root Entry
clsid
000c1084-0000-0000-c000-000000000046
type_literal
root
clsid_literal
on
sid
0
size
18368
type_literal
stream
size
6399
name
\x05DigitalSignature
sid
53
type_literal
stream
size
20
name
\x05MsiDigitalSignatureEx
sid
52
type_literal
stream
size
560
name
\x05SummaryInformation
sid
2
type_literal
stream
size
5820302
name
\u4126\u3865\u41be\u4164
sid
1
type_literal
stream
size
312558
name
\u4192\u4472\u3efe\u3d8a\u430d\u43b6\u433e\u44a6
sid
32
type_literal
stream
size
156160
name
\u430b\u4131\u4735\u403e\u46ec\u3a8c
sid
17
type_literal
stream
size
114430
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3aff\u44f0\u3aff\u4464\u4231\u4835
sid
11
type_literal
stream
size
615318
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3aff\u44f0\u3b7f\u412c\u44af\u482a
sid
12
type_literal
stream
size
318
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3aff\u44f0\u3dff\u46a8
sid
15
type_literal
stream
size
318
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3aff\u44f0\u3fbf\u4833
sid
16
type_literal
stream
size
766
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3cbf\u44a6\u3bbf\u41bb\u412f\u4830
sid
13
type_literal
stream
size
1078
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u3cbf\u44a6\u3cbf\u4271\u4832
sid
14
type_literal
stream
size
62464
name
\u430b\u4131\u4735\u403e\u46ec\u3c9e\u4320\u41bb\u4824
sid
10
type_literal
stream
size
1560
name
\u4840\u3b3f\u43f2\u4438\u45b1
sid
49
type_literal
stream
size
204
name
\u4840\u3c9e\u421d\u45fb
sid
46
type_literal
stream
size
100327
name
\u4840\u3f3f\u4577\u446c\u3b6a\u45e4\u4824
sid
51
type_literal
stream
size
5580
name
\u4840\u3f3f\u4577\u446c\u3e6a\u44b2\u482f
sid
50
type_literal
stream
size
76
name
\u4840\u3f7f\u4164\u422f\u4836
sid
48
type_literal
stream
size
4728
name
\u4840\u3fff\u43e4\u41ec\u45e4\u44ac\u4831
sid
3
type_literal
stream
size
4
name
\u4840\u4115\u4478\u42e6\u448c\u41f1\u45ec\u44ac\u4831
sid
35
type_literal
stream
size
72
name
\u4840\u411b\u4327\u3af2\u45f8\u44b7\u4831
sid
40
type_literal
stream
size
18
name
\u4840\u418a\u4337\u4472\u421d\u45fb
sid
4
type_literal
stream
size
4
name
\u4840\u4192\u4472
sid
31
type_literal
stream
size
48
name
\u4840\u41ca\u4330\u3bb1\u423b\u4626\u4237\u421c\u4634\u4468\u4226
sid
5
type_literal
stream
size
42
name
\u4840\u41ca\u4330\u3fb1\u3f12\u4528\u4238\u41b1\u4828
sid
6
type_literal
stream
size
48
name
\u4840\u41ca\u45f9\u46ce\u41a8\u45f8\u3f28\u4528\u4238\u41b1\u4828
sid
7
type_literal
stream
size
372
name
\u4840\u420f\u45e4\u4578\u3b28\u4432\u44b3\u4231\u45f1\u4836
sid
29
type_literal
stream
size
16
name
\u4840\u420f\u45e4\u4578\u4828
sid
28
type_literal
stream
size
14
name
\u4840\u4216\u4327\u4824
sid
37
type_literal
stream
size
560
name
\u4840\u421b\u3d6a\u41b2\u45e4\u4572
sid
42
type_literal
stream
size
804
name
\u4840\u421b\u432a\u45f6\u4735
sid
41
type_literal
stream
size
150
name
\u4840\u421b\u44b0\u4239\u430f\u422f
sid
43
type_literal
stream
size
48
name
\u4840\u421d\u45fb\u45dc\u43fc\u4828
sid
45
type_literal
stream
size
8
name
\u4840\u42cc\u41a8\u3aee\u46f2
sid
18
type_literal
stream
size
128
name
\u4840\u42dc\u4572\u41b7\u45f8
sid
44
type_literal
stream
size
32
name
\u4840\u430b\u4131\u4735
sid
9
type_literal
stream
size
60
name
\u4840\u430d\u4235\u45e6\u4572\u483c
sid
26
type_literal
stream
size
528
name
\u4840\u430d\u43e4\u42b2
sid
25
type_literal
stream
size
540
name
\u4840\u430f\u422f
sid
30
type_literal
stream
size
222
name
\u4840\u4452\u45f6\u43e4\u3baf\u423b\u4626\u4237\u421c\u4634\u4468\u4226
sid
33
type_literal
stream
size
150
name
\u4840\u4452\u45f6\u43e4\u3faf\u3f12\u4528\u4238\u41b1\u4828
sid
34
type_literal
stream
size
1116
name
\u4840\u448c\u44f0\u4472\u4468\u4837
sid
19
type_literal
stream
size
664
name
\u4840\u448c\u45f1\u44b5\u3b2f\u4472\u4327\u4337\u4472
sid
21
type_literal
stream
size
2112
name
\u4840\u448c\u45f1\u44b5\u3baf\u4239\u45f1
sid
22
type_literal
stream
size
6292
name
\u4840\u448c\u45f1\u44b5\u482f
sid
20
type_literal
stream
size
24
name
\u4840\u4495\u43a6\u4219\u4435\u45ac\u4336\u4472\u4836
sid
36
type_literal
stream
size
224
name
\u4840\u44ca\u3f33\u4128\u41b5\u482b
sid
8
type_literal
stream
size
48
name
\u4840\u44de\u456a\u41e4\u4828
sid
47
type_literal
stream
size
4
name
\u4840\u454c\u4128\u4237\u448f\u41ef\u4568
sid
23
type_literal
stream
size
188
name
\u4840\u4559\u44f2\u4568\u4737
sid
39
type_literal
stream
size
60
name
\u4840\u4596\u3bec\u43ec\u3c68\u45a4\u482b
sid
38
type_literal
stream
size
156
name
\u4840\u460c\u45f6\u4432\u418a\u4337\u4472
sid
24
type_literal
stream
size
56
name
\u4840\u464e\u4468\u3db7\u44e4\u4333\u42b1
sid
27
ExifTool file metadata
MIMEType
image/vnd.fpx

ModifyDate
2015:07:03 02:42:52

Template
Intel;1033

Title
Installation Database

FileType
FPX

Author
Dataram, Inc.

Comments
RAMDisk is a Windows utility that emulates the functionality of a hard disk using system RAM.

CodePage
Windows Latin 1 (Western European)

FileTypeExtension
fpx

Words
2

Keywords
Windows RAM Disk

CreateDate
2015:07:03 02:42:52

Security
Read-only recommended

Software
Windows Installer XML (3.7.1224.0)

Pages
200

RevisionNumber
{D2870978-43BF-4F07-A546-DCFB3A4FCC3B}

Subject
Windows RAMDisk Software

File identification
MD5 d0b8c36b31668848f57e1daed5abd9ce
SHA1 46139ef8ccee0aacd16a281722b6276d72bed64b
SHA256 102b555901653e0f0b822b97a12517ec42dfb3525ccc6fa5c1d63f3a57fcdb64
ssdeep
196608:BWY66y9nOznyR6UjztdqpXZ96MBQuzIF:V+WnlgDQXU

File size 6.9 MB ( 7274496 bytes )
File type Windows Installer
Magic literal
CDF V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Installation Database, Subject: Windows RAMDisk Software, Author: Dataram, Inc., Keywords: Windows RAM Disk, Comments: RAMDisk is a Windows utility that emulates the functionality of a hard disk using system RAM., Template: Intel

TrID Microsoft Windows Installer (98.5%)
Generic OLE2 / Multistream Compound File (1.4%)
Tags
msi signed

VirusTotal metadata
First submission 2015-07-30 05:14:32 UTC ( 2 years, 5 months ago )
Last submission 2017-07-01 13:31:42 UTC ( 6 months, 3 weeks ago )
File names Dataram_RAMDisk_4_4_0_RC3420170701-15470-1v4i9jq.msi
Dataram_RAMDisk_4_4_0_RC3e.msi
Dataram_RAMDisk_4_4_0_RC34.sae.msi
182d85.msi
Dataram_RAMDisk_4_4_0_RC34.msi
1- Dataram_RAMDisk_4_4_0_RC34.msi
Dataram_RAMDisk_4_4_0_RC34.msi
9db52.msi
Dataram_RAMDisk_4_4_0_RC34.msi
e3dc68a.msi
Dataram_RAMDisk_4_4_0.msi
dataram_ramdisk_4_4_0_rc34.msi
Dataram_RAMDisk_4_4_0_RC34.msi
filename
5d599.msi
22f03c5.msi
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!