Setup.exe

Online Media Technologies Ltd.

The program is a setup application that uses the Inno Setup installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from www.afterdawn.com a web site host known to distribute potentially unwanted software operated by AfterDawn.
Publisher:
Online Media Technologies Ltd.   (signed by Online Media Technologies Ltd.)

Description:
AVS Video Tools 5.5 Setup

Version:
5.5.2.672

MD5:
833b5aa0e34d41e500eef96b5f58eac2

SHA-1:
bf0d2a0b273848b501775f01ac237dcac6ddbc60

SHA-256:
31c3ce9f798ea2e33fcc430b09947d92e040a318a432d0a0fb5092579570f3be

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:59:34 AM UTC  (today)

File size:
46.2 MB (48,429,168 bytes)

Installer:
Inno Setup

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/18/2006 3:00:00 AM

Valid to:
5/19/2007 2:59:59 AM

Subject:
CN=Online Media Technologies Ltd., OU=Secure Application Development, O=Online Media Technologies Ltd., L=London, S=London, C=UK

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
12A47E6820E07077467BA524513D590A

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
786432:AOjNH1wlQG4+/W2lxoM8IxtaueDNxgZWvfTBz7qqW/x1CtySE8m+YG6+JyVmD9nw:rjR1wlR4+/Bo0xAu4yIB+Cx9YG6PVmri

Entry address:
0x97F0

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, D6, 98, FF, FF, E8, DD, AA, FF, FF, E8, 00, CD, FF, FF, E8, 47, CD, FF, FF, E8, 3E, F3, FF, FF, E8, A5, F4, FF, FF, 33, C0, 55, 68, 9A, 9E, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 50, 9E, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 5A, FA, FF, FF, 8D, 55, F0, 33, C0, E8, C0, D1, FF, FF, 8B, 55, F0, B8, D4, BD, 40, 00, E8, 87, 99, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D4, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
8.0000

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file Setup.exe has been seen being distributed by the following URL.

http://www.afterdawn.com/software/.../download.cfm?version_id=3614&software_id=1186&mirror_id=0&installer=0&perion=0&air_installer=0

Scan Setup.exe - Powered by Reason Core Security