syncsetup.exe

The withSIX.com client

SIX Networks GmbH

This is a self-extracting archive and installer. The file has been seen being downloaded from auth.withsix.com.
Publisher:
SIX Networks GmbH  (signed and verified)

Product:
The withSIX.com client

Version:
1.7.14

MD5:
f64400730626d70ab9d012c5b960a094

SHA-1:
71ecc4c7149f79fb6960a9d498ef9ae55395c412

SHA-256:
a034469bbed24436e257d607f921c07513d3fcd17840a031d4bac9415ebebe77

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 5:48:20 AM UTC  (today)

File size:
69.5 MB (72,843,248 bytes)

Product version:
1.7.14

Copyright:
Copyright © 2016 SIX Networks GmbH

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\syncsetup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/18/2016 4:00:00 PM

Valid to:
1/18/2019 3:59:59 PM

Subject:
CN=SIX Networks GmbH, O=SIX Networks GmbH, STREET=Heimgartenstrasse 15, L=Starnberg, S=Bavaria, PostalCode=82319, C=DE

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6EC4134E4725401865957B10DED05CFA

File PE Metadata
Compilation timestamp:
8/17/2016 4:20:58 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
1572864:sAPb8dpJsYbC8vEK8fEEzCYvJPqkyBwW1nlQqqq7VMl/AHCmgcmYYdk:s+QI8vEbfEEuYtq7hJjqq7il/AHvxmLk

Entry address:
0x9F36

Entry point:
E8, 90, 04, 00, 00, E9, 8E, FE, FF, FF, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 58, 00, 00, 00, C7, 06, F0, D3, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, F8, D3, 41, 00, C7, 01, F0, D3, 41, 00, C3, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 25, 00, 00, 00, C7, 06, 0C, D4, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, 14, D4, 41, 00, C7, 01, 0C, D4, 41, 00, C3, 55, 8B, EC, 56, 8B, F1, 8D, 46, 04, C7, 06, D0, D3, 41, 00, 83...
 
[+]

Entropy:
7.9986  (probably packed)

Code size:
108.5 KB (111,104 bytes)

The file syncsetup.exe has been seen being distributed by the following URL.

https://auth.withsix.com/api/downloads/.../latest2?type=0

Scan syncsetup.exe - Powered by Reason Core Security