snagit.exe

Snagit 13

TechSmith Corporation

This is a setup program which is used to install the application. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
TechSmith Corporation  (signed and verified)

Product:
Snagit 13

Version:
13.0.0.6094

MD5:
196411c478790c5387d3656f91c600de

SHA-1:
bd132d8689c3a1a871ec02b32214dca502158b4d

SHA-256:
dcaeb30c948520776220831d896e4f5c3d91e0ed780ac8dfbcc3c5407d05fc2c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/30/2024 10:18:49 AM UTC  (today)

File size:
86.7 MB (90,862,784 bytes)

Product version:
13.0.0.6094

Copyright:
Copyright (c) TechSmith Corporation. All rights reserved.

Original file name:
Bootstrapper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\snagit.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
4/2/2015 3:00:00 AM

Valid to:
4/6/2018 3:00:00 PM

Subject:
CN=TechSmith Corporation, O=TechSmith Corporation, L=Okemos, S=MI, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0405D56C46C5C7254AC1464FC2CF4A1F

File PE Metadata
Compilation timestamp:
9/3/2015 6:51:16 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
1572864:QoxMUu/cYD7ai0G4oOFr37T8fkyx1fiw0aELXD0zZLkypb/nKh3pcmhl9:rxDHYD2e4nFr37TQkiiwoLXAz+4GZc8/

Entry address:
0x2A809

Entry point:
E8, 95, 03, 00, 00, E9, 80, FE, FF, FF, 3B, 0D, 04, 90, 46, 00, F2, 75, 02, F2, C3, F2, E9, 1F, 07, 00, 00, 55, 8B, EC, EB, 1F, FF, 75, 08, E8, AD, 6C, 00, 00, 59, 85, C0, 75, 12, 83, 7D, 08, FF, 75, 07, E8, F6, 08, 00, 00, EB, 05, E8, D2, 08, 00, 00, FF, 75, 08, E8, 24, 6D, 00, 00, 59, 85, C0, 74, D4, 5D, C3, 55, 8B, EC, FF, 75, 08, E8, FF, 08, 00, 00, 59, 5D, C3, 55, 8B, EC, F6, 45, 08, 01, 56, 8B, F1, C7, 06, 98, F3, 45, 00, 74, 0A, 6A, 0C, 56, E8, D8, FF, FF, FF, 59, 59, 8B, C6, 5E, 5D, C2, 04, 00, CC...
 
[+]

Entropy:
7.9987  (probably packed)

Code size:
291.5 KB (298,496 bytes)

The file snagit.exe has been seen being distributed by the following 11 URLs.

http://dw.uptodown.com/dwn/6Hg06GvHgnzUjgYEDaTo4F636Crq6vHjOk9AbYfCZk_TbfE_kJJmH-7cbEJhwfUjeSNPKmHOm2LCYM5Mj1XImFjCFZmefqzm6Ge_PtG5RihCnVP_KXvXjtbXeNB3fW2m/AcNBmS1FSzvUoxReZwdzvDW6aSWC9cvnICbsoujYzHvRlNYyedquf8blgjhCEjCi3XS208BhzZ8YsYYNfu0PVicayNPnAueaB00uR-6I62b3IY2mgaRVHU4-l8yko8XU/.../

Scan snagit.exe - Powered by Reason Core Security