conemusetup.160724.exe

ConEmu

Open Source Developer, ConEmu-Maximus5

This is a setup and installation application. The file has been seen being downloaded from download.fosshub.com and multiple other hosts.
Publisher:
ConEmu-Maximus5  (signed by Open Source Developer, ConEmu-Maximus5)

Product:
ConEmu

Description:
ConEmu Installer

Version:
160724

MD5:
6ceb9e05e9d6b4f363c30cf238752ef0

SHA-1:
90890c3d0e50b059d99f0c3d4b8182914be352cc

SHA-256:
79f2895d3d339688fd9d8992cd38a680631cb36ad472f98a9d3d3c2b3eeb22b0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 5:11:44 PM UTC  (today)

File size:
5.3 MB (5,505,568 bytes)

Product version:
160724

Copyright:
© ConEmu.Maximus5@gmail.com

Original file name:
ConEmuSetup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\conemusetup.160724.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
5/2/2016 4:31:18 AM

Valid to:
8/5/2016 5:00:00 PM

Subject:
E=ConEmu.Maximus5@gmail.com, CN="Open Source Developer, ConEmu-Maximus5", O=Open Source Developer, C=RU

Issuer:
CN=Certum Code Signing CA SHA2, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
3E7F6708F415D35803FA526792E35BB4

File PE Metadata
Compilation timestamp:
7/25/2016 1:49:24 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
98304:Yt5ePhR9VffKL8FPmRVyuAS4sKMEaZT/Gtr8F:Y5wbJVa0hS4sKbaZT2QF

Entry address:
0x1110

Entry point:
55, 89, E5, 83, EC, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, 64, 13, 41, 00, E8, F8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 83, EC, 08, C7, 04, 24, 01, 00, 00, 00, FF, 15, 64, 13, 41, 00, E8, D8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 53, 83, EC, 14, 8B, 45, 08, 8B, 00, 8B, 00, 3D, 91, 00, 00, C0, 77, 3B, 3D, 8D, 00, 00, C0, 72, 4B, BB, 01, 00, 00, 00, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 08, 00, 00, 00, E8, 5B, 47, 00, 00, 83, F8, 01, 0F, 84, 03, 01, 00, 00, 85, C0...
 
[+]

Entropy:
7.2498

Packer / compiler:
MingWin32

Code size:
20.5 KB (20,992 bytes)

The file conemusetup.160724.exe has been seen being distributed by the following 2 URLs.

https://download.fosshub.com/Protected/expiretime=1472315564;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Db25FbXUuaHRtbA==/f674bac9de1246f7b5c64f7f16736780be73c2a5984ca57a2c62142970df5fca/.../ConEmuSetup.160724.exe

https://download.fosshub.com/Protected/expiretime=1470975027;badurl=aHR0cDovL3d3dy5mb3NzaHViLmNvbS9Db25FbXUuaHRtbA==/288a21d918920682b8bc2d3ee7befa1eefd4439a030f000b9be92ebcdeb608ab/.../ConEmuSetup.160724.exe

Scan conemusetup.160724.exe - Powered by Reason Core Security