× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: ecd0e0c6982640c1276154535b6fdf7e710675241592b213d0bb7dcc4112052a
File name: WakeOnLanFreeSetup.exe
Detection ratio: 0 / 55
Analysis date: 2015-11-09 18:47:57 UTC ( 3 years, 4 months ago ) View latest
Antivirus Result Update
AegisLab 20151109
Yandex 20151109
AhnLab-V3 20151109
Alibaba 20151109
ALYac 20151109
Antiy-AVL 20151109
Arcabit 20151109
Avast 20151109
AVG 20151109
Avira (no cloud) 20151109
AVware 20151109
Baidu-International 20151109
BitDefender 20151109
Bkav 20151109
ByteHero 20151109
CAT-QuickHeal 20151109
ClamAV 20151109
CMC 20151109
Comodo 20151109
Cyren 20151109
DrWeb 20151109
Emsisoft 20151109
ESET-NOD32 20151109
F-Prot 20151109
F-Secure 20151109
Fortinet 20151109
GData 20151109
Ikarus 20151109
Jiangmin 20151109
K7AntiVirus 20151109
K7GW 20151109
Kaspersky 20151109
Malwarebytes 20151109
McAfee 20151109
McAfee-GW-Edition 20151109
Microsoft 20151109
eScan 20151109
NANO-Antivirus 20151109
nProtect 20151109
Panda 20151109
Qihoo-360 20151109
Rising 20151109
Sophos AV 20151109
SUPERAntiSpyware 20151109
Symantec 20151109
Tencent 20151109
TheHacker 20151108
TotalDefense 20151109
TrendMicro 20151109
TrendMicro-HouseCall 20151109
VBA32 20151109
VIPRE 20151109
ViRobot 20151109
Zillya 20151109
Zoner 20151109
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Authenticode signature block and FileVersionInfo properties
Copyright
Copyright © 2001 - 2015 EMCO. All rights reserved.

Product EMCO WakeOnLan Free
File version 1.3.3
Description EMCO WakeOnLan Free Setup
Comments http://emcosoftware.com/
Signature verification Signed file, verified signature
Signing date 4:47 PM 8/6/2015
Signers
[+] EMCO ehf.
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer VeriSign Class 3 Code Signing 2010 CA
Valid from 1:00 AM 3/31/2014
Valid to 12:59 AM 4/30/2016
Valid usage Code Signing
Algorithm sha1RSA
Thumbprint 7CAACF26FF7F63F2CCCF4C00C920509C0D4A6B29
Serial number 23 CA 05 C5 80 14 1B DA E6 7D 09 3B AC 33 80 52
[+] VeriSign Class 3 Code Signing 2010 CA
Status Valid
Issuer VeriSign Class 3 Public Primary Certification Authority - G5
Valid from 1:00 AM 2/8/2010
Valid to 12:59 AM 2/8/2020
Valid usage Client Auth, Code Signing
Algorithm sha1RSA
Thumbprint 495847A93187CFB8C71F840CB7B41497AD95C64F
Serial number 52 00 E5 AA 25 56 FC 1A 86 ED 96 C9 D4 4B 33 C7
[+] VeriSign
Status Valid
Issuer VeriSign Class 3 Public Primary Certification Authority - G5
Valid from 1:00 AM 11/8/2006
Valid to 12:59 AM 7/17/2036
Valid usage Server Auth, Client Auth, Email Protection, Code Signing
Algorithm sha1RSA
Thumbprint 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
Serial number 18 DA D1 9E 26 7D E8 BB 4A 21 58 CD CC 6B 3B 4A
Counter signers
[+] Symantec Time Stamping Services Signer - G4
Status Valid
Issuer Symantec Time Stamping Services CA - G2
Valid from 1:00 AM 10/18/2012
Valid to 12:59 AM 12/30/2020
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 65439929B67973EB192D6FF243E6767ADF0834E4
Serial number 0E CF F4 38 C8 FE BF 35 6E 04 D8 6A 98 1B 1A 50
[+] Symantec Time Stamping Services CA - G2
Status Valid
Issuer Thawte Timestamping CA
Valid from 1:00 AM 12/21/2012
Valid to 12:59 AM 12/31/2020
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 6C07453FFDDA08B83707C09B82FB3D15F35336B1
Serial number 7E 93 EB FB 7C C6 4E 59 EA 4B 9A 77 D4 06 FC 3B
[+] Thawte Timestamping CA
Status Valid
Issuer Thawte Timestamping CA
Valid from 1:00 AM 1/1/1997
Valid to 12:59 AM 1/1/2021
Valid usage Timestamp Signing
Algorithm md5RSA
Thumbrint BE36A4562FB2EE05DBB3D32323ADF445084ED656
Serial number 00
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2015-08-06 15:47:28
Entry Point 0x00005AEA
Number of sections 4
PE sections
Overlays
MD5 c3f9ccfb8a09fff5511a7e6956a31287
File type data
Offset 52186112
Size 7864
Entropy 7.38
PE imports
GetStdHandle
GetConsoleOutputCP
GetFileAttributesW
FreeEnvironmentStringsA
DeleteCriticalSection
GetCurrentProcess
GetConsoleMode
GetLocaleInfoA
FreeEnvironmentStringsW
SetStdHandle
GetCPInfo
GetStringTypeA
WriteFile
GetSystemTimeAsFileTime
HeapReAlloc
GetStringTypeW
GetOEMCP
LocalFree
FormatMessageW
LoadResource
InterlockedDecrement
SetLastError
RemoveDirectoryW
IsDebuggerPresent
HeapAlloc
GetModuleFileNameA
UnhandledExceptionFilter
TlsGetValue
MultiByteToWideChar
MoveFileExW
SetUnhandledExceptionFilter
SetEnvironmentVariableA
TerminateProcess
WriteConsoleA
SetEndOfFile
GetCurrentThreadId
InterlockedIncrement
WriteConsoleW
InitializeCriticalSectionAndSpinCount
HeapFree
EnterCriticalSection
SetHandleCount
LoadLibraryW
FreeLibrary
QueryPerformanceCounter
GetTickCount
TlsAlloc
FlushFileBuffers
LoadLibraryA
RtlUnwind
GetStartupInfoA
CreateDirectoryW
DeleteFileW
GetProcAddress
GetProcessHeap
EnumResourceNamesW
CompareStringW
CompareStringA
GetTimeZoneInformation
CreateFileW
GetFileType
TlsSetValue
CreateFileA
ExitProcess
LeaveCriticalSection
GetLastError
LCMapStringW
GetConsoleCP
FindResourceW
LCMapStringA
GetEnvironmentStringsW
SizeofResource
GetCurrentProcessId
LockResource
GetCommandLineW
WideCharToMultiByte
HeapSize
GetCommandLineA
RaiseException
TlsFree
SetFilePointer
ReadFile
CloseHandle
GetACP
GetModuleHandleW
GetEnvironmentStrings
IsValidCodePage
HeapCreate
GetTempPathW
VirtualFree
Sleep
VirtualAlloc
UuidCreate
UuidToStringW
RpcStringFreeW
CommandLineToArgvW
MessageBoxW
Ord(205)
Ord(74)
Ord(169)
Ord(141)
Ord(88)
Ord(70)
Ord(8)
Ord(232)
CoUninitialize
CoInitialize
Number of PE resources by type
RT_ICON 16
RT_RCDATA 3
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 19
NEUTRAL 3
PE resources
ExifTool file metadata
UninitializedDataSize
0

Comments
http://emcosoftware.com/

InitializedDataSize
52110336

ImageVersion
0.0

ProductName
EMCO WakeOnLan Free

FileVersionNumber
1.3.3.797

LanguageCode
Neutral

FileFlagsMask
0x003f

FileDescription
EMCO WakeOnLan Free Setup

ImageFileCharacteristics
No relocs, Executable, 32-bit

CharacterSet
Unicode

LinkerVersion
9.0

FileTypeExtension
exe

MIMEType
application/octet-stream

Subsystem
Windows GUI

FileVersion
1.3.3

TimeStamp
2015:08:06 16:47:28+01:00

FileType
Win32 EXE

PEType
PE32

ProductVersion
1.3.3

SubsystemVersion
5.0

OSVersion
5.0

FileOS
Windows NT 32-bit

LegalCopyright
Copyright 2001 - 2015 EMCO. All rights reserved.

MachineType
Intel 386 or later, and compatibles

CompanyName
EMCO Software

CodeSize
74752

FileSubtype
8

ProductVersionNumber
1.3.3.797

EntryPoint
0x5aea

ObjectFileType
Driver

File identification
MD5 ad9f8957f6184ec2ad052354dfd31c8c
SHA1 387acd49f6bab01bb750bdb739aacefd1686aff0
SHA256 ecd0e0c6982640c1276154535b6fdf7e710675241592b213d0bb7dcc4112052a
ssdeep
1572864:si15K8q+CF4ugKWWopSEUnG8cdCipUc9qQ/:si1hqF2KWX8rG8cAGUo1

authentihash 5d6158c66a08ab6cad6f7eae9bd7f856663670619d5531e707ac9120c4b1aba3
imphash 8e55f2d68beb6ad4c08e854b69f8c330
File size 49.8 MB ( 52193976 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID InstallShield setup (35.0%)
Win32 EXE PECompact compressed (generic) (33.8%)
Win64 Executable (generic) (22.4%)
Win32 Executable (generic) (3.6%)
OS/2 Executable (generic) (1.6%)
Tags
peexe signed overlay

VirusTotal metadata
First submission 2015-08-07 12:18:56 UTC ( 3 years, 7 months ago )
Last submission 2017-02-06 09:35:10 UTC ( 2 years, 1 month ago )
File names WakeOnLanFreeSetup.exe
WakeOnLanFreeSetup.exe
713604
WakeOnLanFreeSetup.exe
ECD0E0C6982640C1276154535B6FDF7E710675241592B213D0BB7DCC4112052A
WakeOnLanFreeSetup.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!