f-lux_f.lux_1.0_anglais_278130.exe

Michael Herf

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Michael Herf  (signed and verified)

MD5:
728d222dfd2b6ae2986e2ae69bd1a6f8

SHA-1:
37f4e5c5e18901564ebf32c76efd1db0bd61ed43

SHA-256:
5a4029d224accfa790b79705b8185bc8e167d89b4bbddee85e50b4e56672c4e7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 7:44:08 PM UTC  (today)

File size:
545.2 KB (558,328 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\f-lux_f.lux_1.0_anglais_278130.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
11/20/2008 1:00:00 AM

Valid to:
11/21/2009 12:59:59 AM

Subject:
CN=Michael Herf, O=Michael Herf, STREET="1315 S. Carmelina #201", L=Los Angeles, S=CA, PostalCode=90025, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
5066269CA42CFF413FBFC60A2183C4D3

File PE Metadata
Compilation timestamp:
2/8/2008 10:25:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:TO00VcxXkF24U2pQux2aYBkiCes7IPGAIR94eO4eMDrmvV6P:TO00ux0M1lI2aFiEAUPOfMDKvV6P

Entry address:
0x30BE

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 58, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 3F, 42, 00, E8, E1, 2A, 00, 00, A3, 64, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 28, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 4C, 91, 40, 00, 68, 60, 36, 42, 00, E8, 98, 27, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 86, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22 KB (22,528 bytes)

The file f-lux_f.lux_1.0_anglais_278130.exe has been discovered within the following program.

F.lux  by justgetflux
Publisher's description - “f.lux fixes this: it makes the color of your computer's display adapt to the time of day, warm at night and like sunlight during the day. It's even possible that you're staying up too late because of your computer. You could use f.”
stereopsis.com/flux
4% remove it
 
Powered by Should I Remove It?

The file f-lux_f.lux_1.0_anglais_278130.exe has been seen being distributed by the following 7 URLs.

http://gsf-cf.softonic.com/37f/4e5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=79169&instance=softonic_br&type=PROGRAM&Expires=1485695115&Signature=gRgSXtm8HNp~6kLGlF6FgkhLT2TdXRga9rt8b-~84RZGBn2tDi0TbrbwtVRblA8kKPeX7eK5ZeMsQr9N3gCwdDMdS5YXSAmBzLhWPuu9hp-5qHwuxAulaqWuTyNltzj6fOmZ3l8421uJxPhWcKB5dKXSpfa-vf4SLhKXS5v4lQk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=flux-setup.exe

http://gsf-cf.softonic.com/37f/4e5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=79169&instance=softonic_fr&type=PROGRAM&Expires=1480060877&Signature=dF56ibPzh72RhBbUijJ-621PbhHTOHiImJvUamt1AY2eQlsIMomiB6JEgiNnajYbqZ9ZcKF0~yzdVOtPzcmLMgi1OIT2G-W5Gox0oVDbyD2UbE~2TtnQMP1Ob84dnHEje94F3sm7Ou-qRUqnXA8aCCSodlCzKyY8QIuI2dwI5pg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=flux-setup.exe

http://gsf-cf.softonic.com/37f/4e5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=79169&instance=softonic_br&type=PROGRAM&Expires=1480315999&Signature=HXxrILkpmGWuM65b-qzW5HrJtk6kXGgJGX~cvKHDCpD7G9XlFwIHEEV-umegjQT6KfYPAIjkYfGADrke2PF8hAxzxk0XDDP-SVm2c0nUnVtaWbR5vo8UB9JtEW6kFs6In5yjTlwD2k~eQIiMafkdQoUo730ztJB5roMjp9FteXA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=flux-setup.exe

Scan f-lux_f.lux_1.0_anglais_278130.exe - Powered by Reason Core Security