bethesdanetlauncher_setup.exe

Bethesda.net Launcher

Zenimax Media Inc.

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.filesdeliverybits.com and multiple other hosts.
Publisher:
Bethesda Softworks   (signed by Zenimax Media Inc.)

Product:
Bethesda.net Launcher

Description:
Bethesda.net Launcher Setup

MD5:
f36a3de369516f752c9c7a51ea0f3ea2

SHA-1:
a8f9fd4187470aa0f406c9bbaa0a55cf987cc8b7

SHA-256:
49520dfe51dd74a0f7981aabfa54d61abef7b21b592e1343c177c2bfc9200052

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:43:58 PM UTC  (today)

File size:
7.1 MB (7,493,336 bytes)

Product version:
1.0

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bethesdanetlauncher_setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
12/2/2015 4:00:00 PM

Valid to:
1/3/2017 3:59:59 PM

Subject:
CN=Zenimax Media Inc., OU=Zenimax Online Studios, O=Zenimax Media Inc., L=Rockville, S=Maryland, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5703A83169AFEF8304E753B714065E6A

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:WVSGAsnzQ6zkrCzfp2FEMB38KPYHwrBGOXIsWFOputuwKjXoaLzuiNJ9moBixD1/:f+UrCz0FRFQMkpvp0kEzLNJ9E5tTl

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9918

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file bethesdanetlauncher_setup.exe has been seen being distributed by the following 20 URLs.

http://www.filesdeliverybits.com/hEm4BvAu08JnxButFNaino6VIPlrg l5P1U66fOwNpf4onVPRyGcyqF1mQ2TJ iA2eJRdOtBhMFqnyVNEOE_iXPhUtD9ME4rOurbQ7E 3jTiZaeUw13bZk5nov6kb_YMSUdyk3Y30DzzdBUmsXz8ceN y2Csh2fnz4vyg4jmq5pWudF_ujBATkWVZKnkGjLzf9j2pFS05i5Z6HgbYluxK4VKaP22Q==-GzwAAEQ3F5NammCxGIym4cPhcDwcHHLg8EVtyUEtcMgJfUFB9ryxfTqxKQ7BKFNiijoU_00s7MGtNGd8AA==

http://ow.ly/h8QU302lJjv

http://www.bulksharetown.com/Uc88m6b6J3Eu8RKP0lPeJxjLNKiTxyD71M3CGFCqAFJoNhh2Z5sjDzIXYWJRZFuZv4V4QSLtFFr4_w1u2UIBLjZTvSSMneHiaU XvUATY7D9KPVXux3CRYCvTOi_NqX_tIl2TI1oMDpCvuv8O3L1M5FZvcQFtmTrdJIQu3R7WOgykKhhb88T12VhLHsg6x2pIXBuAFXKxyPZO0rHePpPpN Ec9ZqCA==-GzwAAEQ3F5NammCxGIym4cPhcDwcHHLg8EVtyUEtcMgJfUFB9ryxfTqxKQ7BKFNiijoU_00s7MGtNGd8AA==

http://www.bulksharetown.com/ GfibD9lMKYB191V2Niy3DmE1tjq1Rh94TJiwPwPWOujg7jHTr8Ms8OGKX6mIAk7biT3oLhbBWxh8C1aX4v0XcQXsdhnxV8V3IN31OUICxqHW87p2WBdqJm6o4l3pkpT9buQG6DFkPt6XvbM3jltRW3Y 03kJA2oTEBImrdy2Qbx19uyCGKMPhDdhld82NfOB OvcB7hJa1V4OOYmaQxAqbekwpdzQ==-GzwAAEQ3F5NammCxGIym4cPhcDwcHHLg8EVtyUEtcMgJfUFB9ryxfTqxKQ7BKFNiijoU_00s7MGtNGd8AA==

http://r2.computerbild.de/exec/r2r.pl?m=w-cobi;u=http://d.computerbild.de/downloads/.../BethesdaNetLauncher_Setup.exe

http://click.mailer.elderscrollsonline.com/?qs=c68d90e34df9668ee925bdfcd9e13e46b5894c1fa1d6b052ea25e6e071537a68

http://rockpapershotgun.digidip.net/visit?url=http://download.cdp.bethesda.net/BethesdaNetLauncher_Setup.exe&ppref=https://.../

http://www.bulksharetown.com/fJXtDlNlpDYPgTaOf5DltdIz5OjcMN9TXBZviIsKGDL AnpcJDRSMDLsNrRL6W973yRYa3gkwaW9kBhhzFCODkrgl5nlHTAZdyyCTQv8pMmlfBp4TybR7OYc AhgyyZXAssDLQt2LvlBx5C1271S4Totj4 jxDX0JxS5ZeMYYQePE4A5vjyTaL8pz_pjQOrwzKN5eGP76xdK_PlMaPFnazEfUJJ1rQ==-GzwAAEQ3F5NammCxGIym4cPhcDwcHHLg8EVtyUEtcMgJfUFB9ryxfTqxKQ7BKFNiijoU_00s7MGtNGd8AA==

http://l.facebook.com/l.php?u=http://.../BethesdaNetLauncher_Setup.exe

https://www.dropbox.com/s/.../BethesdaNetLauncher_Setup.exe

http://www.bulksharetown.com/AiNdmLLHFKB8KsXLlvaDODUspPjiSy6u6VoW65ZHI_ Sd6Zmvyb7Pn79lZKUI4BMMRVQKfQeIXfs3_3zFyYBwdzVRdZyuNxvASXh0HaFnZbwMroWvffceHgSUKnjE6O0JsCNCiFVlFCV u7t0sU rRoqgq1agQrgty2cg8wY2f9w8MjtRixtjj723G9hXpVbuMfyg0N6r5lTqbIkpDOSCE9eHPHPOQ==-GzwAAEQ3F5NammCxGIym4cPhcDwcHHLg8EVtyUEtcMgJfUFB9ryxfTqxKQ7BKFNiijoU_00s7MGtNGd8AA==

http://rockpapershotgun.digidip.net/visit?url=http://download.cdp.bethesda.net/BethesdaNetLauncher_Setup.exe&ppref=https://.../

http://ow.ly/QvlV302f9Bo

http://rockpapershotgun.digidip.net/visit?url=http://download.cdp.bethesda.net/BethesdaNetLauncher_Setup.exe&ppref=https://.../

http://ow.ly/Vscg302hfjZ

http://ow.ly/f4Pu302f9pn

Scan bethesdanetlauncher_setup.exe - Powered by Reason Core Security