iTunesSetup.exe

iTunes

Apple Inc.

This is a setup and installation application. The file has been seen being downloaded from www.tamindir.com and multiple other hosts.
Publisher:
Apple Inc.  (signed and verified)

Product:
iTunes

Description:
iTunes Installer

Version:
12.2.0.145

MD5:
29221abf693526b8b6e8871e290aba8c

SHA-1:
c15b3cd6c82cb28093bab1cb80491e75cdafae9a

SHA-256:
b89e52397ff775c1b88317951900e459b1956e39035a401c77a511712b0ec95d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 4:23:35 AM UTC  (today)

File size:
105.6 MB (110,737,712 bytes)

Product version:
12.2.0.145

Copyright:
© Apple Inc. All Rights Reserved.

Original file name:
iTunesSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\itunessetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/23/2013 5:00:00 PM

Valid to:
7/23/2015 4:59:59 PM

Subject:
CN=Apple Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Apple Inc., L=Cupertino, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47DE2F9FBF7A1D4191F45773FA113E1D

File PE Metadata
Compilation timestamp:
6/29/2015 5:56:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1572864:rq6yQrhfnaOcMq7RWtKmd+gFr/oMyc5bk9CByNGDL94W8ERAqv9EXvJtdfCJ:rPykcN7RWtKmdXxwNjm4WzJv6BCJ

Entry address:
0xBA63

Entry point:
E8, F4, 55, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, A3, 14, 8B, 41, 00, 5D, C3, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 00, 6C, 41, 00, 33, C5, 89, 45, FC, 83, A5, D8, FC, FF, FF, 00, 53, 6A, 4C, 8D, 85, DC, FC, FF, FF, 6A, 00, 50, E8, E7, D1, FF, FF, 8D, 85, D8, FC, FF, FF, 89, 85, 28, FD, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, 2C, FD, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89...
 
[+]

Entropy:
7.9998  (probably packed)

Code size:
71.5 KB (73,216 bytes)

The file iTunesSetup.exe has been seen being distributed by the following 44 URLs.

http://www.tamindir.com/indir/MjAxNS0wOC0yNyAxMjo0NzowNQ==/itunes/windows/.../

http://www.techspot.com/downloads/downloadnow/.../?evp=edb2ed37deb36891a0c0bc2ade110514&file=1

ftp://172.24.49.64/rayong/.../itunessetup.exe

http://192.168.0.100/coria/.../itunessetup12.2.exe

http://www.techspot.com/downloads/downloadnow/.../?evp=e49b810a8ed42d6ca9a56614938d6c8c&file=1

https://api.ipsw.me/v2.1/iTunes/win/latest/.../dl

http://www.filepuma.com/file2/1436034207c9107/itunes_32bit_12.2.0/.../

https://secure-appldnld.apple.com/iTunes11/.../iTunesSetup.exe

https://secure-appldnld.apple.com/itunes12/.../iTunesSetup.exe

http://filehippo.com/download/file/.../

http://www.tamindir.com/indir/MjAxNS0wOS0xNiAxNTozNzo1Nw==/itunes/windows/.../

http://appldnld.apple.com/iTunes11/.../iTunesSetup.exe

http://www.ispazio.net/?dl_name=https://secure-appldnld.apple.com/itunes12/.../itunessetup.exe

http://www.filepuma.com/file2/1436019882c9107/itunes_32bit_12.2.0/.../

https://secure-appldnld.apple.com/itunes12/.../iTunesSetup.exe

http://www.tamindir.com/indir/MjAxNS0wOC0xNiAwMToxOTo0Nw==/itunes/windows/.../

http://filehippo.com/download/file/.../

https://secure-appldnld.apple.com/iTunes12/.../iTunesSetup.exe

http://www.tamindir.com/indir/MjAxNS0wOS0wNiAxMjozMzozNA==/itunes/windows/.../

http://www.techspot.com/downloads/downloadnow/.../?evp=689d2c2725621b3ca235313f1a6f57a5&file=1

https://secure-appldnld.apple.com/itunes12/.../iTunesSetup.exe

Latest 30 of 44 download URLs