character_wizard_1_0_0.exe

iSpring Character Wizard

iSpring Solutions, Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from www.ispringsolutions.com.
Publisher:
iSpring Solutions, Inc.  (signed and verified)

Product:
iSpring Character Wizard

Version:
1.0.0.18

MD5:
c52fa269e7ff310114f92624257a58d2

SHA-1:
bcb45f159f6d9ddd5af783481e1f079192289fc9

SHA-256:
cddd593ef605d62d81ffccdd4844bffda3dad0f755f050d472363fd903b698ad

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 3:30:37 AM UTC  (today)

File size:
3.8 MB (4,015,416 bytes)

Product version:
1.0.0.18

Copyright:
Copyright © 2005-2014 iSpring Solutions, Inc. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/20/2012 9:00:00 PM

Valid to:
5/21/2015 8:59:59 PM

Subject:
CN="iSpring Solutions, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="iSpring Solutions, Inc.", L=New York, S=NewYork, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3E5952ED85016219996EF8EF80B1DCBC

File PE Metadata
Compilation timestamp:
6/5/2014 6:07:39 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:W87STnWSeeNKlgiT7X9AF8HQVYxXty2HNUTwJjWmB25BH:KDFRcP3N5jy8A

Entry address:
0x50012

Entry point:
E8, FF, A8, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 57, 33, DB, 6A, 07, 33, C0, 59, 8D, 7D, E4, 89, 5D, E0, F3, AB, 39, 5D, 14, 75, 18, E8, 64, 3B, 00, 00, C7, 00, 16, 00, 00, 00, E8, A0, 89, 00, 00, 83, C8, FF, E9, BC, 00, 00, 00, 8B, 7D, 10, 56, 8B, 75, 0C, 3B, FB, 74, 1C, 3B, F3, 75, 18, E8, 3D, 3B, 00, 00, C7, 00, 16, 00, 00, 00, E8, 79, 89, 00, 00, 83, C8, FF, E9, 94, 00, 00, 00, C7, 45, EC, 42, 00, 00, 00, 89, 75, E8, 89, 75, E0, 81, FF, FF, FF, FF, 3F, 76, 09, C7, 45, E4, FF...
 
[+]

Code size:
2.2 MB (2,278,400 bytes)

The file character_wizard_1_0_0.exe has been seen being distributed by the following URL.

Scan character_wizard_1_0_0.exe - Powered by Reason Core Security