openfm_setup.exe

GG Network S.A.

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
GG Network S.A.  (signed and verified)

MD5:
297316c890fdf2852c7a43c5de30bb93

SHA-1:
2ece2d4066211e7cde1292052df259f681724d0a

SHA-256:
aaf475db091b68058c6aa2ee30ea33b2c3aeea5e7f64d8148b3342bba8312cfd

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/26/2024 7:43:51 PM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
TROJ_GEN.F47V1127
7.2.212

File size:
18.6 MB (19,506,928 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\caly syf\other\openfm_setup.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/7/2012 1:00:00 AM

Valid to:
3/8/2014 12:59:59 AM

Subject:
CN=GG Network S.A., O=GG Network S.A., L=Warsaw, S=Warsaw, C=PL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1E4A8091705C037FB9B7D67698682916

File PE Metadata
Compilation timestamp:
4/10/2010 2:19:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:qKBV6Fdcr78v2oxadGrcOfw+ReghRzWCAMx1U0GJFaG0K1ONht7bACopgy+gKfax:qK6jVv2FdGVfwWRzskU7B/4ntHlo8IP

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file openfm_setup.exe has been seen being distributed by the following 50 URLs.

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1476036582&Signature=XRoJItMdXviTTUKVNxruKVZM-6Gg149BKymgzThdqBJBPY~TZ697UWNzSz21dUKwrb1hLt~o-OxnimLfCjYKVEuwaVYKQ7XrEK-RoluMOtMNFDwG7PSIdq0Ep5NhXmuuZH6xHmTWRYrkCg9A-KoHOVsWwPhSUSDFV9UJq7Slt7I_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=openfm_setup.exe

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1487447149&Signature=Z2mmiG4msjwtbaH87ai4bKWupIggKnhtTb-B75HAgm0YHIhb934YuEtCo0ixZf978R-h6-bC8Uz4~WE5mQua95MuHwoYvBcZ4Mm2oE9abPHC4lagT~-3M0r9bGS1wZ5Sed7QmxQBjDp~5udzMsB5zd6u9W2I2OrOWwJWAKRPxyI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=openfm_setup.exe

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1476152755&Signature=JCwTxri0N9QQ1vT9UGyl9wS6VjB2D0UuU~89kLrxtHP68WXWNOON542nnr1l9NVrUJCb~9eOyZwqRdqR3krU~8RDPZ8B2dBbfPBY9Fi-dSQ7XkwD2EOpw4cLNNild1ywQ5CcxqJCzY4DbPj08i7avpzOP9TwE4~013NmAS~162s_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=openfm_setup.exe

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1478320886&Signature=Krvpq1kauMnvDGXOgSi3z3LexNNMjyxqfWG1XaL-x7dEkz2HJTFLaRf~jKyIq87BML35WyLJCThO5hJBISFc6SuEdcxw-uhnXFdfHDUF0xlXNPotlYL7PJTUlUpshgQaL71v7eWRD8-9boW5E0jtuG9wkDtS5or1zbVori9-z78_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=openfm_setup.exe

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1440026738&Signature=iJlSxxne6yyUG2rRIFW3hrVJCcbGTqBFv8~n8nbARVryNB2wlFz97Dzcj0ByPdMiwFFj-WnSJd~JuA6mq3oTeBt6A-sJT4WgNfZFdMIHjGyqSGtntq6T~WiyQgvyuei6-irw4GsEFsVXlSKdr2OqJ9RNhqIjDEjU6E-IGy-CCkc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=openfm_setup.exe

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1476727609&Signature=hFZTI5FhbtIqZxVKffkabbZup3pC8hT7u3~X7T5gQVkM1TR3NF63JAi3QAOaWhJFIEHDD3NgUZoZejGjh9jSa0WiOToFhI3nLET5aiF~8Qdfbt2W8P6qMXsXBGyV6k7I3m9TGxklLXIGb0bsD8gEhlEq-8bw99Nv0PE-ZDo5hqg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=openfm_setup.exe

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1478401063&Signature=cYKDMYEAMiM7EvLSJJ8z32AC4Rskg9UzB6QUt~955yWslhxA7OmDJKq61JXE49h4FP1bYu5MsmwMFRQfCF9GruaaHyYj2etY2HS4zHKz8kjVc9KTDShKWv~TguZfqiMOeRFyVMsjIZCD1nFpAFemzHXdiob7CYFWc8MbSiSIUNI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=openfm_setup.exe

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1442296440&Signature=CyFqT0eV1l8A2pXylBTnBlZeNLP33hKVyLtW8ZJLNsNTpqflW2XgXp9DaChJIG8bKCxkYuzbXXOG2YqapXQjmJxMXRZg7976MTqG~Ffyaj~SQbuoDA-J5UBzEKKg5gD2YpM-9jruTim5d7jO8wj7xisltyl-f-gUihD8fz0wSQc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=openfm_setup.exe

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1477031278&Signature=QL8udDtfYU61RM6~j-di4PISusF8oa5jze58r1-UodGvfSbm-bTDAfj5y0fxBkrI1XO-UeBXZopscFrQuJPDL6YbOjpm65adOByaj9mIn1ETZ9GvfFmQZDjuByqoQWaul1DLB6~sM869bmFODFNpPgyYlrzAqQ2XotOrEYqQJUU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=openfm_setup.exe

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1435953205&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=MOvGTRTmNmPnrFSmPCd2n3QK58cSyYlcfW2~ZTtlM1QwMf49CeQk0j-bgL5Z6PZms0VbZnUD0qkuW6bPq7p09umc0HQZrx4pA9cgwZwqMFZx5naz15OBNNVtwFGW9Nb4r2vCWKJqHG-pFZ15opfuNuanW-i7RD52dQ6yrtIry9I_&filename=openfm_setup.exe

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1445319190&Signature=BJxQWwOgpSB4gmM4nUgrz4HPsDjsZnjdrFheKIL3VZHfrDWnNl2LiSRYXjdADnBScUVe0uqGuMtcSpoJiNCU2ymt3GNxQFgS4xkbD~HjadJ~ONN6WaN7Hm~J9Znn60wZqS8ZGrFTkCyUe-jTjVH-m8K5lA2MIBMkRGzE451Hn3Q_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=openfm_setup.exe

http://gsf-cf.softonic.com/2ec/e2d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=130184&instance=softonic_pl&type=PROGRAM&Expires=1440634686&Signature=K-7giUy1imz7RwNIFTnuEwz0Xt~wglPiFjNZGHzeZQghSktViJi2hGUzQ-EmhnS1UcxCrJ9Lnqn-ywrDd8YnJUWkcMrgIoNi~eSnef3Z-2jbiMGPM1y5PUJsCrSJTzvknkGjH0MKrNtak~y1Lh6EuTsvRIL1qgVZG~7Da5hjI6I_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=openfm_setup.exe

temp:openfm_setup.exe

Latest 30 of 50 download URLs

Scan openfm_setup.exe - Powered by Reason Core Security