syncsetup.exe

The withSIX.com client

SIX Networks GmbH

This is a setup and installation application. The file has been seen being downloaded from auth.withsix.com.
Publisher:
SIX Networks GmbH  (signed and verified)

Product:
The withSIX.com client

Version:
1.7.11

MD5:
07b24f3c3ef38e2b45042cce28388396

SHA-1:
99d08ee23c39f1900995803e0f48b04d6e57a500

SHA-256:
30cd488fd57a8da81ec5e6dec85260fab2c71a1cd8fc0a116c4ca9b736fa15b0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 3:33:17 PM UTC  (today)

File size:
67.2 MB (70,448,112 bytes)

Product version:
1.7.11

Copyright:
Copyright © 2016 SIX Networks GmbH

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\syncsetup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/18/2016 4:00:00 PM

Valid to:
1/18/2019 3:59:59 PM

Subject:
CN=SIX Networks GmbH, O=SIX Networks GmbH, STREET=Heimgartenstrasse 15, L=Starnberg, S=Bavaria, PostalCode=82319, C=DE

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6EC4134E4725401865957B10DED05CFA

File PE Metadata
Compilation timestamp:
8/17/2016 4:20:58 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
1572864:DMrPwjjt8CFUtRf9YsMlNnp67MLkmJqVin+fJS215YPyGUSaAWAnw:Dk++Rf9YyqJq4q715YPyjJAxw

Entry address:
0x9F36

Entry point:
E8, 90, 04, 00, 00, E9, 8E, FE, FF, FF, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 58, 00, 00, 00, C7, 06, F0, D3, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, F8, D3, 41, 00, C7, 01, F0, D3, 41, 00, C3, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 25, 00, 00, 00, C7, 06, 0C, D4, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, 14, D4, 41, 00, C7, 01, 0C, D4, 41, 00, C3, 55, 8B, EC, 56, 8B, F1, 8D, 46, 04, C7, 06, D0, D3, 41, 00, 83...
 
[+]

Entropy:
7.9986  (probably packed)

Code size:
108.5 KB (111,104 bytes)

The file syncsetup.exe has been seen being distributed by the following URL.

https://auth.withsix.com/api/downloads/.../latest2?type=0

Scan syncsetup.exe - Powered by Reason Core Security