533093_stp.exe

Sublime Text 2

Sublime HQ Pty Ltd

This is a self-extracting archive and installer. The file has been seen being downloaded from 188.138.9.44 and multiple other hosts.
Publisher:
Sublime HQ Pty Ltd  (signed and verified)

Product:
Sublime Text 2

Description:
Sublime Text 2 Setup

MD5:
8f85cb66d2c3e94f77b212fb52b939b5

SHA-1:
42237bddd675103fcc14597e0a8299e70ab588fd

SHA-256:
89a593d9fc5f12557c8dbfad010fbd909e7a04cd60037ad6e204b2cb457e9418

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 11:02:22 AM UTC  (today)

File size:
5.3 MB (5,599,128 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\533093_stp.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/5/2012 9:00:00 PM

Valid to:
4/6/2014 8:59:59 PM

Subject:
CN=Sublime HQ Pty Ltd, O=Sublime HQ Pty Ltd, STREET=11/10-12 Grantham St, L=Burwood, S=NSW, PostalCode=2134, C=AU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
28FEC2F3C951E331CD10AD25D0E66192

File PE Metadata
Compilation timestamp:
6/10/2010 11:33:52 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:GtIt+Ce5eFnP66ZIxkZJogWSu/WDDTWCVtTdeM76seCgQ3IJUa4J:Gtn5eFnGx3O9beMwQ348

Entry address:
0x163C4

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 54, 55, 41, 00, E8, 70, 04, FF, FF, 33, C0, 55, 68, 91, 6A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 4D, 6A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, A6, EF, FF, FF, E8, B1, EA, FF, FF, 8D, 55, EC, 33, C0, E8, FB, 87, FF, FF, 8B, 55, EC, B8, A8, D6, 41, 00, E8, A6, EA, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, A8, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
85 KB (87,040 bytes)

The file 533093_stp.exe has been seen being distributed by the following 50 URLs.

http://188.138.9.44/.../Sublime_Text_2.0.2_Setup.exe

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://blogattach.naver.net/1b8e07b4a1fdff230de18dbc84651b63c19b648d0f/20140706_249_blogfile/.../Sublime Text 2.0.2 Setup.exe

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://188.138.70.230/.../Sublime_Text_2.0.2_Setup.exe

http://filehippo.com/download/file/.../

https://doc-0k-88-docs.googleusercontent.com/docs/securesc/18h0oogin7h63ecuh6db8d6lrcsk44uu/efud1urltri5kshg93a6g6oqgsoedog5/1473724800000/.../01111001546654398288/0B7sVw9ogG5FDbzFfUFlpRTFrUUk?e=download

http://filehippo.com/it/download/file/.../

http://filehippo.com/download/file/.../

http://85.25.74.170/.../Sublime_Text_2.0.2_Setup.exe

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://www.techspot.com/downloads/downloadnow/.../?evp=17d2ef3e8580987b69af76cb1de67a71&file=1

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

Latest 30 of 117 download URLs

Scan 533093_stp.exe - Powered by Reason Core Security