× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 6e4f464aa3c5d70bdd76f28e89d948c20535708d4206b8b9e88af5486083f586
File name: cispremium_installer_10555_51.exe
Detection ratio: 0 / 67
Analysis date: 2019-02-19 12:04:43 UTC ( 4 weeks, 1 day ago ) View latest
Antivirus Result Update
Acronis 20190213
Ad-Aware 20190219
AegisLab 20190219
AhnLab-V3 20190219
Alibaba 20180921
ALYac 20190219
Antiy-AVL 20190219
Arcabit 20190219
Avast 20190219
Avast-Mobile 20190219
AVG 20190219
Avira (no cloud) 20190219
Babable 20180918
Baidu 20190215
BitDefender 20190219
Bkav 20190219
CAT-QuickHeal 20190218
ClamAV 20190219
CMC 20190219
Comodo 20190219
CrowdStrike Falcon (ML) 20181023
Cybereason 20190109
Cylance 20190219
Cyren 20190219
DrWeb 20190219
eGambit 20190219
Emsisoft 20190219
Endgame 20190215
ESET-NOD32 20190219
F-Prot 20190219
F-Secure 20190219
Fortinet 20190219
GData 20190219
Ikarus 20190219
Sophos ML 20181128
Jiangmin 20190219
K7AntiVirus 20190219
K7GW 20190219
Kaspersky 20190219
Kingsoft 20190219
Malwarebytes 20190219
MAX 20190219
McAfee 20190219
McAfee-GW-Edition 20190219
Microsoft 20190219
eScan 20190219
NANO-Antivirus 20190219
Palo Alto Networks (Known Signatures) 20190219
Panda 20190218
Qihoo-360 20190219
Rising 20190219
SentinelOne (Static ML) 20190203
Sophos AV 20190219
SUPERAntiSpyware 20190213
Symantec 20190219
Symantec Mobile Insight 20190207
TACHYON 20190219
Tencent 20190219
TheHacker 20190217
Trapmine 20190123
TrendMicro 20190219
Trustlook 20190219
VBA32 20190219
ViRobot 20190219
Webroot 20190219
Yandex 20190219
Zillya 20190218
ZoneAlarm by Check Point 20190219
Zoner 20190219
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Authenticode signature block and FileVersionInfo properties
Copyright
2005-2018 COMODO. All rights reserved.

Product COMODO Internet Security
File version 11, 0, 0, 6744
Description COMODO Internet Security
Signature verification Signed file, verified signature
Signing date 12:35 PM 12/17/2018
Signers
[+] Comodo Security Solutions, Inc.
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer COMODO Code Signing CA 2
Valid from 12:00 AM 01/04/2018
Valid to 11:59 PM 01/04/2019
Valid usage Code Signing
Algorithm sha1RSA
Thumbprint 76FBABF1EADED3B91DD7A76A6678301F1F87AA97
Serial number 00 C5 14 4C F5 E5 35 F7 48 A9 AF A6 FC 38 4C 07 75
[+] COMODO Code Signing CA 2
Status Valid
Issuer UTN-USERFirst-Object
Valid from 12:00 AM 08/24/2011
Valid to 10:48 AM 05/30/2020
Valid usage Code Signing
Algorithm sha1RSA
Thumbprint B64771392538D1EB7A9281998791C14AFD0C5035
Serial number 10 70 9D 4F F5 54 08 D7 30 60 01 D8 EA 91 75 BB
[+] UTN-USERFirst-Object
Status Valid
Issuer AddTrust External CA Root
Valid from 08:09 AM 06/07/2005
Valid to 10:48 AM 05/30/2020
Valid usage All
Algorithm sha1RSA
Thumbprint 8AD5C9987E6F190BD6F5416E2DE44CCD641D8CDA
Serial number 42 1A F2 94 09 84 19 1F 52 0A 4B C6 24 26 A7 4B
[+] The USERTrust Network™
Status Valid
Issuer AddTrust External CA Root
Valid from 10:48 AM 05/30/2000
Valid to 10:48 AM 05/30/2020
Valid usage Server Auth, Client Auth, Email Protection, Code Signing, Timestamp Signing, EFS, IPSEC Tunnel, IPSEC User
Algorithm sha1RSA
Thumbprint 02FAF3E291435468607857694DF5E45B68851868
Serial number 01
Counter signers
[+] COMODO SHA-1 Time Stamping Signer
Status Valid
Issuer UTN-USERFirst-Object
Valid from 12:00 AM 12/31/2015
Valid to 06:40 PM 07/09/2019
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 03A5B14663EB12023091B84A6D6A68BC871DE66B
Serial number 16 88 F0 39 25 5E 63 8E 69 14 39 07 E6 33 0B
[+] UTN-USERFirst-Object
Status Valid
Issuer AddTrust External CA Root
Valid from 08:09 AM 06/07/2005
Valid to 10:48 AM 05/30/2020
Valid usage All
Algorithm sha1RSA
Thumbrint 8AD5C9987E6F190BD6F5416E2DE44CCD641D8CDA
Serial number 42 1A F2 94 09 84 19 1F 52 0A 4B C6 24 26 A7 4B
[+] The USERTrust Network™
Status Valid
Issuer AddTrust External CA Root
Valid from 10:48 AM 05/30/2000
Valid to 10:48 AM 05/30/2020
Valid usage Server Auth, Client Auth, Email Protection, Code Signing, Timestamp Signing, EFS, IPSEC Tunnel, IPSEC User
Algorithm sha1RSA
Thumbrint 02FAF3E291435468607857694DF5E45B68851868
Serial number 01
Packers identified
F-PROT 7Z, Unicode, UTF-8
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2016-02-18 14:47:52
Entry Point 0x0001D0F6
Number of sections 5
PE sections
Overlays
MD5 1c18eb0fb90c19f7d8dbbd0b44ce2a65
File type data
Offset 1732608
Size 3849592
Entropy 8.00
PE imports
FreeSid
AllocateAndInitializeSid
CheckTokenMembership
GetDeviceCaps
GetCurrentObject
DeleteDC
CreateFontIndirectW
SelectObject
CreateCompatibleBitmap
GetObjectW
SetStretchBltMode
CreateCompatibleDC
DeleteObject
StretchBlt
SetThreadLocale
GetStdHandle
GetDriveTypeW
WaitForSingleObject
LockResource
CreateJobObjectW
EncodePointer
GetFileAttributesW
SetInformationJobObject
GetLocalTime
DeleteCriticalSection
GetCurrentProcess
GetConsoleMode
UnhandledExceptionFilter
LoadLibraryExW
FreeEnvironmentStringsW
GetLocaleInfoW
SetStdHandle
FindResourceExA
WideCharToMultiByte
LoadLibraryW
WriteFile
GetSystemTimeAsFileTime
HeapReAlloc
GetStringTypeW
SetEvent
LocalFree
FormatMessageW
ResumeThread
InitializeCriticalSection
OutputDebugStringW
FindClose
TlsGetValue
SetFileAttributesW
GetEnvironmentVariableW
SetLastError
GetUserDefaultUILanguage
LoadResource
RemoveDirectoryW
IsDebuggerPresent
ExitProcess
GetModuleFileNameA
lstrcmpiW
SetProcessWorkingSetSize
GetSystemDefaultUILanguage
GetSystemDefaultLCID
InterlockedDecrement
MultiByteToWideChar
SetFilePointerEx
CreateThread
SetEnvironmentVariableW
GetSystemDirectoryW
GetExitCodeThread
SetUnhandledExceptionFilter
MulDiv
IsProcessorFeaturePresent
GetFileInformationByHandle
GetSystemDirectoryA
DecodePointer
TerminateProcess
GetVersion
GetModuleHandleExW
SetCurrentDirectoryW
GlobalAlloc
GetDiskFreeSpaceExW
SetEndOfFile
GetCurrentThreadId
LeaveCriticalSection
WriteConsoleW
InitializeCriticalSectionAndSpinCount
HeapFree
EnterCriticalSection
TerminateThread
lstrcmpiA
GetVersionExW
GetExitCodeProcess
QueryPerformanceCounter
TlsAlloc
FlushFileBuffers
LoadLibraryA
RtlUnwind
ExitThread
GetFileSize
GetStartupInfoW
CreateDirectoryW
DeleteFileW
WaitForMultipleObjects
GetProcessHeap
AssignProcessToJobObject
lstrcpyW
GetModuleFileNameW
ExpandEnvironmentStringsW
FindNextFileW
ResetEvent
FindFirstFileW
lstrcmpW
GetProcAddress
CreateEventW
CreateFileW
GetFileType
TlsSetValue
HeapAlloc
InterlockedIncrement
GetLastError
SystemTimeToFileTime
LCMapStringW
lstrlenA
GlobalFree
GetConsoleCP
GetEnvironmentStringsW
lstrlenW
CreateProcessW
GetQueuedCompletionStatus
SizeofResource
CompareFileTime
GetCurrentProcessId
CreateIoCompletionPort
SetFileTime
GetCommandLineW
GetCPInfo
HeapSize
GetCommandLineA
SuspendThread
RaiseException
TlsFree
SetFilePointer
ReadFile
CloseHandle
GetACP
GetModuleHandleW
IsValidCodePage
GetTempPathW
VirtualFree
Sleep
IsBadReadPtr
VirtualAlloc
GetOEMCP
SysAllocStringLen
SysFreeString
VariantClear
OleLoadPicture
SysAllocString
SHBrowseForFolderW
ShellExecuteW
SHGetPathFromIDListW
ShellExecuteExW
SHGetFileInfoW
SHGetSpecialFolderPathW
SHGetMalloc
SetFocus
GetParent
EndDialog
SystemParametersInfoW
DefWindowProcW
KillTimer
GetMessageW
ScreenToClient
ShowWindow
MessageBeep
SetWindowPos
GetClassNameA
wvsprintfW
GetSystemMetrics
SetWindowLongW
IsWindow
GetMenu
GetWindowRect
EnableWindow
UnhookWindowsHookEx
CharUpperW
MessageBoxA
LoadIconW
GetWindowDC
GetWindow
GetSysColor
DispatchMessageW
GetDC
GetKeyState
ReleaseDC
SendMessageW
GetWindowLongW
DrawIconEx
DestroyWindow
GetClientRect
SetTimer
GetDlgItem
DrawTextW
CallWindowProcW
EnableMenuItem
ClientToScreen
CallNextHookEx
wsprintfA
CreateWindowExA
LoadImageW
DialogBoxIndirectParamW
SetWindowTextW
GetWindowTextW
SetWindowsHookExW
GetSystemMenu
GetWindowTextLengthW
CreateWindowExW
wsprintfW
CopyImage
PtInRect
CreateStreamOnHGlobal
CoCreateInstance
CoInitialize
Number of PE resources by type
RT_ICON 42
RT_GROUP_ICON 2
RT_VERSION 1
RT_MANIFEST 1
Number of PE resources by language
RUSSIAN 22
UKRAINIAN DEFAULT 21
ENGLISH US 3
PE resources
Debug information
ExifTool file metadata
UninitializedDataSize
0

LinkerVersion
11.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
11.0.0.6744

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

FileDescription
COMODO Internet Security

ImageFileCharacteristics
Executable, 32-bit

CharacterSet
Windows, Latin1

InitializedDataSize
1587200

EntryPoint
0x1d0f6

MIMEType
application/octet-stream

LegalCopyright
2005-2018 COMODO. All rights reserved.

FileVersion
11, 0, 0, 6744

TimeStamp
2016:02:18 15:47:52+01:00

FileType
Win32 EXE

PEType
PE32

ProductVersion
11, 0, 0, 6744

SubsystemVersion
5.1

OSVersion
5.1

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
COMODO

CodeSize
144384

ProductName
COMODO Internet Security

ProductVersionNumber
11.0.0.6744

FileTypeExtension
exe

ObjectFileType
Executable application

File identification
MD5 9712e1b496ebc837f531dca4ce6d4b94
SHA1 c5840388a4c46d0a4cc21fb84674f24e80ac452b
SHA256 6e4f464aa3c5d70bdd76f28e89d948c20535708d4206b8b9e88af5486083f586
ssdeep
98304:w3oeoi7dSeyh2qQ0Lkmxiyc3ybpQcUdhOVBzHB7Yr8bRXlahkHviwEa0IK6+E:w3oeoYSeyoS5iZybpn2kd7tbRXIkF0IW

authentihash 22a7ed569fb104df7d4e462ac7eb9e3c772fa2cf24b339695d63231c41b04742
imphash cb2f8861ae9e888fc248b97ed817726f
File size 5.3 MB ( 5582200 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Microsoft Visual C++ compiled executable (generic) (73.2%)
OS/2 Executable (generic) (8.9%)
Generic Win/DOS Executable (8.8%)
DOS Executable Generic (8.8%)
Tags
peexe signed overlay

VirusTotal metadata
First submission 2019-01-04 14:18:51 UTC ( 2 months, 2 weeks ago )
Last submission 2019-03-06 09:31:41 UTC ( 2 weeks ago )
File names cispremium_installer_10313_d1.exe
cispremium_installer_5764_af.exe
cispremium_installer_5997_92.exe
cispremium_installer_10555_51.exe
Comodo Internet Security 11.0.0.6744 - cispremium_installer.exe
cispremium_installer_10554_60.exe
cispremium_installer_10555_51.exe
cispremium_installer_10555_51.exe
cispremium_installer_5962_fe.exe
cispremium_installer_6100_08.exe
cispremium_installer_6950_2d.exe
http---download.comodo.com-cis-download-installs-1000-partners-cispremium_installer_10555_51.exe
cispremium_installer.exe
cispremium_installer_10299_7b.exe
cispremium_installer_10555_51.exe
cispremium_installer_10555_51.exe
cispremium_installer.exe
cispremium_installer_10555_51.exe
cispremium_installer_6114_38.exe
cispremium_installer_10555_51.exe
cispremium_installer_6964_c4.exe
cispremium_installer_10386_e7.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Created mutexes
Runtime DLLs