249923_211240_chromesetup.exe

Хром

OOO Yandex

This is a setup and installation application. The file has been seen being downloaded from o-soft.ru and multiple other hosts.
Publisher:
The Chromium Authors  (signed by OOO Yandex)

Product:
Хром

Version:
15.0.874.121

MD5:
7b4b6b132a5e1e15dc73c3fcd447cee5

SHA-1:
aa17f8485fb71107b8257d962a811fb950a09b0c

SHA-256:
3c5f27ddef8f7ed0192aeaf2deda80d069b7f12d02e493e4862ae6e3ff2dc69c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:23:09 AM UTC  (today)

File size:
24.2 MB (25,398,600 bytes)

Product version:
15.0.874.121

Copyright:
Copyright (C) 2006-2011 The Chromium Authors. All Rights Reserved.

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\249923_211240_chromesetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/5/2010 4:00:00 AM

Valid to:
2/5/2013 3:59:59 AM

Subject:
CN=OOO Yandex, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=OOO Yandex, L=Moscow, S=Moscow, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3769815A97A8FB411E005282B37878E3

File PE Metadata
Compilation timestamp:
11/17/2011 5:41:00 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:HUn+bkw8mIkCwPVh4fsqibYdCMCZ3t+qm8:0Bw8fwwoMCMCZYqz

Entry address:
0x2D90

Entry point:
6A, 00, FF, 15, A4, 10, 40, 00, 50, E8, 82, FE, FF, FF, 83, C4, 04, 50, FF, 15, A0, 10, 40, 00, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 01, 85, C0, 74, 09, 83, 79, 0C, 01, 7C, 03, 8B, 00, C3, 33, C0, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 53, 56, 8B, F1, 8B, 06, 85, C0, 74, 0D, 50, FF, 15, A8, 10, 40, 00, C7, 06, 00, 00, 00, 00, 8B, 44, 24, 0C, 8D, 5E, 0C, 53, 50, C7, 46, 04, F0, 10, 40, 00, C7, 46, 10, 00, 00, 00, 00, C7, 03, 00, 00, 00, 00, C6, 46, 14, 00, C6, 46, 15, 00, C6, 46, 16, 00...
 
[+]

Packer / compiler:
FASM v1.3x

Code size:
10 KB (10,240 bytes)

The file 249923_211240_chromesetup.exe has been seen being distributed by the following 5 URLs.

http://o-soft.ru/.../download.php?id=164

http://soft.mydiv.net/win/dlfile43575_249923/.../211240_ChromeSetup.exe

Scan 249923_211240_chromesetup.exe - Powered by Reason Core Security