spm17intwr.exe

Steganos Password Manager 17

Steganos Software GmbH

This is a setup program which is used to install the application. The file has been seen being downloaded from www.softonic.com and multiple other hosts.
Publisher:
Steganos Software GmbH  (signed and verified)

Product:
Steganos Password Manager 17

Version:
17.0.0 Rev 11424

MD5:
3959780addcb68ab66541a56f472a18f

SHA-1:
9bbd98be3d233f00c77c64774fc317ff11466238

SHA-256:
532a8f8c1485a21cd907896b00afb61d2bd468a280ac0414a9524857d9b5f0cc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/6/2024 5:01:24 AM UTC  (today)

File size:
17.4 MB (18,233,032 bytes)

Product version:
17.0.0 Rev 11424

Copyright:
Copyright (c) 2015 Steganos Software GmbH

Original file name:
setupwrapper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\spm17intwr.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/10/2014 8:10:01 AM

Valid to:
11/3/2017 10:55:47 AM

Subject:
E=certificates@steganos.com, CN=Steganos Software GmbH, O=Steganos Software GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112127389AB528A3A8EC995621C824069818

File PE Metadata
Compilation timestamp:
8/25/2015 4:15:22 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:ZHDU41AmCzVXPnFxDR6bF6Z0yrhznfx6oHKda5ScCAYvHzicb:Zj0tPnTC6RhLfUoHKda59CAiTT

Entry address:
0x10D66

Entry point:
E8, 3F, 8B, 00, 00, E9, A4, FE, FF, FF, 6A, 0C, 68, D0, 86, 42, 00, E8, A0, 44, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, C8, C5, 42, 00, 03, 75, 43, 6A, 04, E8, 29, 8D, 00, 00, 59, 83, 65, FC, 00, 56, E8, 51, 8D, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, 72, 8D, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, 15, 8C, 00, 00, 59, C3, 56, 6A, 00, FF, 35, F4, C2, 42, 00, FF, 15, 74, 40, 42, 00, 85, C0, 75, 16, E8, 2E, 28, 00...
 
[+]

Code size:
139.5 KB (142,848 bytes)

The file spm17intwr.exe has been seen being distributed by the following 19 URLs.

http://www.softonic.com/sads/tracker.php?ev=c&co=CO&sid=7a78205fb71dbb2aba699abb0ed2c1a6&upv=1b87767e222807eb4f566032c73c8e1b&z=results&sk=0&abp=1&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA4203D8EC137E1792B4D6DF2EBF0B2011ABD3B7493D72404B710D801189B441B767D843BC4E3A7B8622EFD54C896C6C05BC1AD09108930213CCF5886FBEB2AE8836C0E7E066F46FE194DA995C9D567A57BF658D91379086D58D298D06784098054D3154B23F73DA52E1C53BEF82A3E16E5C7290AEE3F6C4921DD88122DD44EC552EF69320581639704B7605BD03A198FB&h=3F352BBB4FFEE35EF67D0E240374EF678F4DD182FFDB613DB56F29B0270BF07D&directdownload=1&f=83169&d=http://www.segurisoft.es/software/Dwl_portalsa/.../spm17intwr.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=AR&sid=ba46eeb356ab1e17ae915840fe28f2af&upv=f252b0b60a970fe4c8fd5667806bac00&z=results&sk=0&abp=1&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA4203D8EC137E1792B4D6DF2EBF0B2011ABD3B7493D72404B710D801189B441B73C5BE6E07E2BFD237AB83B640C8B6B72099516CD5F125E682E07345392C045BC0C9BCB956C9096D0F2868DEFBA34EE7A6D7690E9D13B9354A4671B0F54B5302EFCCD0C04DC558D967BB4ABD332D789B3C5AF7D90990A3B21D578B4F149521C5B8180F473BB2BAE350B0EDBB0451D42D0&h=D49E6FAD3949968BFC253C02882D46D0F4A31D067632D0FE2008CCD059FE6309&directdownload=1&f=83169&d=http://www.segurisoft.es/software/Dwl_portalsa/.../spm17intwr.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=AR&sid=1f84436b30fff9f5e85e49ec79eb13a8&upv=cf27d327e63af8790ae832464968bf15&z=results&sk=0&abp=1&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA4203D8EC137E1792B4D6DF2EBF0B2011ABD3B7493D72404B710D801189B441B7FC92F7D99EAD2B1BE29918F498969C4506291BF15EEDB25D21BEA9F79E3669299C57E7443D37B27DE7A6481D7EABE77F3CFBF7012EA94B3930FC8E94FC718F0D2D412BC0BD9E4648F215F5567CE24ED0EA486F95D4A06800D5550F84AF7585F9596AD0D16F6BCE9A636E3C3CF7DF78CB&h=F4CC9B78CD795D91288931FBEB410FE32A2BA3B7846156DF84127B26D6C36A5E&directdownload=1&f=83169&d=http://www.segurisoft.es/software/Dwl_portalsa/.../spm17intwr.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=ES&upv=46b08cb25f81a7f1eec553fcbc68dfd9&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA4203D8EC137E1792B4D6DF2EBF0B2011ABD3B7493D72404B710D801189B441B74F0A3D0FB5BD5E52570519598CEBE637D5A895EF7E357C32C78501A105B6D2460D78A5E1B49EF701782AC7699A72E3B877227C69A516A7F8C1CA12CAA9D3927879E7A9A9EC07864327DCF392E467CA37D333240E417B8D7BCB9FA7F8DE73A862D2B8E512254233186F5A40D539B580D8&h=4F45D313F48483AA96D5D8E8A20376324B0F8BA2A9D0555B8689B1B2B193EA30&directdownload=1&f=83169&d=http://www.segurisoft.es/software/Dwl_portalsa/.../spm17intwr.exe

Scan spm17intwr.exe - Powered by Reason Core Security