winzip19-lan.exe

WinZip Computing LLC

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from cdn.winzipfilestorage.com and multiple other hosts.
Publisher:
WinZip  (signed by WinZip Computing LLC)

Product:
WinZip

Version:
1.0.5.a0.1_42753

MD5:
239499264793bcd1bd902b858619f849

SHA-1:
fe941729a332f88c86a89f3af7ccc19065061c5e

SHA-256:
20be1f7f01d4f9f6518f7916da2916d64c5181a1f7692268ef25fd89ce4eb55b

Scanner detections:
15 / 68

Status:
Clean  (15 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/25/2024 3:29:25 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.InstallCore
2015.05.19

Avira AntiVirus
PUA/InstallCore.XS
8.3.1.6

avast!
Malware-gen
2014.9-150811

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.15811

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.InstallCore.DAH
22203

Dr.Web
Trojan.InstallCore.677
9.0.1.0223

ESET NOD32
Win32/InstallCore.ZH potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/InstallCore
8/11/2015

K7 AntiVirus
Adware
13.204.15949

McAfee
Artemis!B371A37C54CD
5600.6677

NANO AntiVirus
Riskware.Win32.InstallCore.dfgmhs
0.30.24.1357

Sophos
Generic PUA BO
4.98

Trend Micro House Call
Suspicious_GEN.F47V0611
7.2.223

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
3.12.26.4

File size:
1 MB (1,083,080 bytes)

Product version:
1.0.5.a0.1_42753

Copyright:
WinZip

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\winzip19-lan.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/10/2015 4:50:10 AM

Valid to:
2/11/2016 4:50:10 AM

Subject:
CN=WinZip Computing LLC, O=WinZip Computing LLC, S=Connecticut, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11213AC849B929DBABC960315B5B9070927F

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:YPxt/WwLGgC89b2hzR1MLutDc9d2iTdz2GibzYl7uX:YZtVL3jutYD2MsYy

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9156

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file winzip19-lan.exe has been seen being distributed by the following 48 URLs.

http://cdn.winzipfilestorage.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=mttjbcIvoAb8g3tVD3kVNXdeHheJbB13q06OqyBN1rc=&downloadAs=winzip19-lan.exe&c=k9v9T8LYPesl2gLjTosnmFf2ydbjTr9l8g2EfFlU/OGV/.../OI0GlsFslk6EINco=

http://d.winziparchives.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=XZG6A8K5SjqaJHS5a1c1TdPnb/JW8RBc5nsaEt5Q6kg=&downloadAs=winzip19-lan.exe&c=2Q5Tgx8IzT18 2xP5mgDG6fINm5uCMzrK1p2hD7kURysu3olwMewBLgaXvp7AiAd4TJ1hnob4dyvy9yIdFOm07/.../cefMM=

http://d.winziparchives.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=fB7n cicYsFEWcnIVRRCpCAXyIKFicRE3J/QG /v2vc=&downloadAs=winzip19-lan.exe&c=Tc39w9R5Jjvb7O3haOqcVLQyqYypW7edMFljJW9 HFLW14ZQfDVmt ynh/PFW2yjNWq/.../3tHN1WmA5TKyFiFCeN GQRh2xeMqaYODy3xVdGa7Ybo52eWvg lSkmHOLGxuqQG6w==

http://d.winziparchives.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=wxqL0RMOIsFPxVeuiVH0fv3J97Ikwy9gbl4uaz18Joo=&downloadAs=winzip19-lan.exe&c=qULkhaKSdSqqDgAlaV5erUYWbhVza1914FpEQMW5UF8BAytvDdKXd DuSpaIFuIX9oM S867oy0yLVawlP5J19VDPZe 4o20V/.../lws0xUjEP7nk4ihKmc80YR0UfSKQD UwoLgtA==

http://www.bulkdownloadstours.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=ztmlvV3fNA/Fhk2K5GvLDROYCBu3ElTEEmtvPSzUrfI=&downloadAs=winzip19-lan.exe&c= RcfvzA4GO2vzD5eDJjPChYrzhwQuhv CXKkh4Xe5yvJxZQBzkTnNLO4AJhkHEdk4yUKBrTL/NwbyZszVZ3aWkaBi5ZV/.../MnyDN 3eQu8BpY=

http://d.winziparchives.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=xyLzLrhz9dG78tOc22xPA6td1No4sgJdeeyuyRUcWQg=&downloadAs=winzip19-lan.exe&c=fmKt1diFmocf4rtM6btWRy7leJey/Dp DQh2hHudWtoORyARhQ/SWYA0NxUvgW/.../XW1eqK 171JsPUezet7zgQD6YhFkvEcHbBbliM7vB88nFtpD5MnmpEwWbY2eJjiw37e AS5jD5U69seSzBVMe0zh1Lm Usd3nm1dCbaWw=

http://d.winziparchives.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=W7iu3ruTgj3xdymx1YiG312tHdCasn2XpEZFGrZjgbU=&downloadAs=winzip19-lan.exe&c=jzunQIOZz 8szju2bcsaYH SROhFIsiVEAXu5 m76A5Y4VuPj6iJh/gcyxjm/l0n5sWGgKAOkkn1gzty8PnxnbNLq/.../y0q6N3fkO92Frg=

http://d.winziparchives.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=8qOHPsy/mr6Z88CVR8n4KOqlXkkOnWVEVxFKYfEMmEY=&downloadAs=winzip19-lan.exe&c=AqRT9trF2hdD2H2yZaoPBKb8N9w9zAcg3eKEIGf/iDIjhy0J/ikyVpb7sWgUOXaW xuGWh41yUkuwyBwMW2qtLN9qmv7BaHGgEY7guplPC1UDdiL1javUzFepxxoFX/7O7Y5//5BFDlysOPpp132YVTVeleTJg/.../Uk8Zs=

http://d.winziparchives.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=k0blFPMYNYVui0mmNmVKvbFRpJQwtiPOGkzJGWEcivY=&downloadAs=winzip19-lan.exe&c=RCe9di8EqP xFQrCAgaoLvFgFla06X4sgFsZpzhIdOdZ7yPWwSOdgoi9jfz0PH2vU1NUky/.../i0pmh 7Bm5jyr8mhF7lXAzQ==

http://d.winziparchives.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=ZwHr3y1x2pVXGFmtCtwFJ13DduYsFlvS2c98dfcK XE=&downloadAs=winzip19-lan.exe&c=bukgvIkKmpuM4IW04GKpF7YG/.../52Bz9mxUe6A6OtbN4kwz8qRau0evpoFJGn1Te46dRZ10mag==

http://d.winziparchives.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=uw3e6Lxp96uftl5IXBb/YfS0QFcdHvw/RTcawl9YxkY=&downloadAs=winzip19-lan.exe&c=/jInnSIBUsX/.../VbQcSDLmsWbZde1nbDLNfpcUBtY74MWGQMxjtpdFwUCTQ5YikIpueLY1nXzsXer9quJ9L84mj78WauVXWK HGEFm6yM114o1vVnoR7vcY=

http://d.winziparchives.com/c?fallback_url=http://download.winzip.com/gl/lan1/winzip19.exe&x=uxgAkD9oIb S8CKXRCxvjoUuG/Z1Gm9S4f/.../Ez8lfsd5WJpNDKMXXjFQwmBUiiDZHyXx8OXv7IWXxVjDKOrBKvSesi4ZkhGDTLJGDF8GBWNcFXynvRrnrTksEnLJ4=

Latest 30 of 48 download URLs

Scan winzip19-lan.exe - Powered by Reason Core Security