setup_galaxy_1.1.10.47.exe

GOG Galaxy

GOG Limited

This is a setup program which is used to install the application. The file has been seen being downloaded from www.bytesendclear.com and multiple other hosts.
Publisher:
GOG.com   (signed by GOG Limited)

Product:
GOG Galaxy

Version:
1.1.10.47

MD5:
87d854819f44c4696deae86716711480

SHA-1:
f34ea23d724d335f31f0bae69640ec63ea000d15

SHA-256:
4063dbc47039bcf153f5dc61a25ebef093ee9e8e54fe2e9178d624d607eeee13

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:56:33 PM UTC  (today)

File size:
134.1 MB (140,619,040 bytes)

Product version:
1.1.10.47

Copyright:
© 2016 GOG Ltd. All rights reserved.

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup_galaxy_1.1.10.47.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
4/2/2015 2:00:00 AM

Valid to:
6/1/2016 2:00:00 PM

Subject:
CN=GOG Limited, O=GOG Limited, L=Nicosia, C=CY

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0B84CDECCABF7D06904BFBE923C3CFEA

File PE Metadata
Compilation timestamp:
4/6/2016 4:39:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3145728:Vr3A1iS9w0i4OgqsnHUFWF3zMWLV0X/DeFtiVPvQes708Nr:0ZZi4O3UHIAojX/DfxvT8Nr

Entry address:
0x117DC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 44, 01, 41, 00, E8, C8, 4D, FF, FF, 33, C0, 55, 68, BE, 1E, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 7A, 1E, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 0E, D5, FF, FF, E8, 5D, D0, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 23, D6, FF, FF, 33, C0, E8, 60, 2E, FF, FF, 8D, 55, EC, 33, C0, E8, A6, A0, FF, FF, 8B, 55, EC, B8, 58, 86...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
65 KB (66,560 bytes)

The file setup_galaxy_1.1.10.47.exe has been seen being distributed by the following 11 URLs.

http://www.bytesendclear.com/ns2CLxhQlz8uM6M6nWheHW9hYDmJKPjvnHevgMf1pGezYEebQ0GRkCxJsaGNUYFjyfMcUMPkC3JSK8sZQ2NYN9_nDnPm6VS0oLArLqL283J94vffZ8eHA dYVUnPhQotdYVN7z224o2NAaByzTdKOvvcloUp24n3Zl6WhZInNCTaABHJrggxsb1iINay3IXpoBoOT3HsbomJ9FSwn7c5qfzxvX4i_mNIoMVRYIGN4kDpb0x3eTTBI6poOv160xLZ8Dprjk4Q03hJrXciQnHmFYTxLJpmEC17wsfcHV9phfWH09GABrPTQUixbfP PUY98RvZctN0vFyArWYvIeCZ43oEK6s_wrpRaiG0gPxtN32 Pd 041oGmDY7Nikyi0FYRR Fn_Qcuq jbiEWIZaxdu5bqo9Bak47hp4i6k278TMSTasJmVLStqy_U0puv9eVT4QAQjGkIsbf5EEcfNyhF4mZtD0Bah8eI c9QxLQpznH0JJJkgdM04vc_Z0Iq6TBVHivLE9gXOhgQixBFtBfHu8EYyYrVmmHg46GfDTOnJwpmqLHndj4cHxG4q1M4jz2MWpHT AilJNSpAtO mQDw9 ZAlw6sjRC641TUhFImth7HNzdL8PLujNxTl7ZY6k8h47Y45U4-G2EAAGRxW0z8JeDJQrs6NmAiBw4tTeAC p6wDeSNKarTXaCcKuHROJ5UBZQ9niusZ_orvI7gHmRNLxmgXRXozSyZjah43uaZePIBVkkpGhKfAA==-E

http://www.bytesendclear.com/ohELnFgE30EVMgIq98WQEoG5CBpIIqDuUfbhOBG KlrMgwUvN7gMSwjdpVLviZVcViWy0dO2S1YvyOnwg45gGN6_iWXOQyQ8PqllUevLNvhrcoVx_AAPj2kFC O69BK9pkCKh81WiDmTjWDOQMPY3zKf9IOO1YS0MRARudkctQ2qAPIklt8OsICkqGl6XLUaeuOWwpon2FFwg5nNTFK3tiSyKdudESkR8ueQPuNH3pGVPLhhrga3fFBDQNVhgnGTWD2NXo2cByNXYx643a3rnRCuz3bhEybZcbYSRz3uYnb_YSgfAa9HdZ48kXJsH87CNmf9DDkFpKIlCjdnDLJL4oMZO07UOPXCIkbz0PxBbr2cx3Hmcfsn91eCHC7roiYueYFb_6kG1dbtVdtBKfeZGGRrPJlaZ9LEiD6kdIfp35QlJexTf2a_s5mXrMAux6YCrhWoBIanI9r6TfUVwp82FEW b7gYw_T3i54dH2VS1fWvM2RB6nXxeu9yVgPh_GYfR_R5GmPza7Zg7_yiVO0XF2XsKRjWMYshy5d0jk7_MaAcNKEOIA_NM_Mg247UFW7pbwK1Hvgdx1jYvLii0etUnxb693iraaPa59S4TblaGq2eCKkwBmw=-G2EAAGRxW0z8JeDJQrs6NmAiBw4tTeAC p6wDeSNKarTXaCcKuHROJ5UBZQ9niusZ_orvI7gHmRNLxmgXRXozSyZjah43uaZePIBVkkpGhKfAA==-E

http://www.bytesendclear.com/WVl6OTRQVzh4YVVWc00ydFNRVVlsTWtKeGIzWnJlSFJSUlRWV0pUSkdWRk5IY2pWUVRWWkxZWFJwWm5CM1RXWWxNa0prVUc4bE0wUW1aVDB4Sm1NOVRISlZSelJQV21OeWEwdDVSVUZoYUc5cmVscFZlamMwT1hoaVdWVlBhMlY0TjBrbE1rSTJZMVpyZEd4cVYxTlJiRmg1TTFKRWNGRWxNa1pNTTBaMVExbzFOM00zTlU5SU1VWkNUVU5PWVZwTWNtdzBWRmtsTWtJMU5Fa2xNa1kyWm5ocmVVcDFaRGwzU1VaUmFsVmxSWG8yWjJvbE1rWTNSVFkxUkRCS1pWRnBRM2h0VjB0UFdqTmFlVmxKSlRKQ1RGTnVjVGRKU2paeGJrcElZVmR5UnlVeVFsRWxNMFFsTTBRbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1abWFXeGxjeTFrYjNkdWJHOWhaQzV3YjNKaFpHNXBhMlJ2WjNKNUxuQnNKVEptUjNKNVNWSnZlbko1ZDJ0aEpUSm1RM2xtY205M1lVUjVjM1J5ZVdKMVkycGhSMmxsY2lVeVprZFBSMGRoYkdGNGVTVXlabWR2WjJkaGJHRjRlUzVsZUdVbVpHOTNibXh2WVdSQmN6MUViMjRsTWpkMEsxTjBZWEoyWlM1bGVHVT0=

http://www.signtowntoday.com/WVl6OTRQVk0xVFVwMWJETTFlVTE0SlRKQ05HWmpabGdsTWtKSmVraG1KVEpHY1ZKUlZFTkdWbGNsTWtaQk5sWkdPVWt5YUVGUE5DVXpSQ1pqUFdOdU9EaGxRM0ZCWkV4aVNUVjVXVTVMWm1GcmJIcElZM1oxUXpGblVXbHBTWEJhVDNkd1FURXhlV1Y2U0cxUmJEVnNkbXhFTXlVeVFqaGFURTlVVm1wd2NtOVdKVEpDYWpOd2J6aElTamxMWkZOdGEwbzBhMFpQVWpGVFNVbFpjRzR3Y1UxQlluQXdlbVJpVjJKWUpUSkdKVEpDTVZCblNUWWxNa0pwYnpOcmFFaGlKVEpDZUNVeVJuaHVjR3B3ZEZRbE1rSk9SRVYwT1hwWWNIaENZWFU1Y1dOWVNFRWxNMFFsTTBRbVpUMHhKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1abWxzWlhNdFpHOTNibXh2WVdRdWNHOXlZV1J1YVd0a2IyZHllUzV3YkNVeVprZHllVWxTYjNweWVYZHJZU1V5WmtONVpuSnZkMkZFZVhOMGNubGlkV05xWVVkcFpYSWxNbVpIVDBkSFlXeGhlSGtsTW1abmIyZG5ZV3hoZUhrdVpYaGxKbVJ2ZDI1c2IyRmtRWE05VkdWeWNtRnlhV0V1WlhobA==

Scan setup_galaxy_1.1.10.47.exe - Powered by Reason Core Security