winzip20-wz.exe

WinZip Computing LLC

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.winzipdownloadfiles.com and multiple other hosts.
Publisher:
WinZip  (signed by WinZip Computing LLC)

Product:
WinZip

Version:
1.0.5.a0.1_60366

MD5:
2e54f81122864c36999a0656235f976a

SHA-1:
278df73e1865dce005a20c29273b83cf058f9afd

SHA-256:
4348ea51f767131de5944f04b78464ed1ada3a75433097ac0deb2dc35028ca1a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 3:36:11 PM UTC  (today)

File size:
1 MB (1,100,992 bytes)

Product version:
1.0.5.a0.1_60366

Copyright:
WinZip

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\winzip20-wz.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/14/2016 11:00:13 AM

Valid to:
1/14/2017 11:00:13 AM

Subject:
CN=WinZip Computing LLC, O=WinZip Computing LLC, L=Mansfield, S=CT, C=US

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211E499D8513CC8715BAD5459440153388

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Vvi+7AQ5JGYl5pcd6sxtNPEx35L/ZDsIt6C:Va+l5JG/d64nPA37sqP

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9195

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file winzip20-wz.exe has been seen being distributed by the following 43 URLs.

http://www.winzipdownloadfiles.com/c?fallback_url=http://download.winzip.com/gl/nkln/winzip20_downwz.exe&x=1p1NhpU3Be0vCV5w blJpNt6csjZtNi7ORU9YRZvycc=&downloadAs=winzip20-wz.exe&c=TaqFj9JkHj0lNYgGoAPSyHv4d4dO5FwA66FB5feiJ2SRxGkd6J76QFUiN SJlz0UO4MDEB5D4r2iZw1laQ9/WNhBPl3oc/OSV9MZQZYNRenk5/.../s5rTMAw06F9gu

http://www.winzipdownloadfiles.com/c?fallback_url=http://download.winzip.com/gl/nkln/winzip20_downwz.exe&x=UY6C4T22sSiBBto9T9PuS48ZtsTJGEFwMAEfypH2Hxo=&downloadAs=winzip20-wz.exe&c=Q/KSwjeDw3ZtMVlWeTdIdEKD1TIhduDPy04OwjwcvlCW1ispB/Py7Xd0nYa41Dp5XF dCkOvSAZ/oHTL8HQN/.../7ydL2D3Qz0aYKKva7lB38e4vW8nUdYVPlxo99B8A

http://www.winzipdownloadfiles.com/c?fallback_url=http://download.winzip.com/gl/nkln/.../ljr9PPWobLGtKILAWt 0JbrRmbuEb2d7tB6h0kLAzejM0t2DB8cUNdDCi7ytLkfILOuuA0AdtPkCeYDA0H2P8jPKLkQdzOy7od9FLIXJVH

http://www.winzipdownloadfiles.com/c?fallback_url=http://download.winzip.com/gl/nkln/winzip20_downwz.exe&x=hHI7GBDGQM9x7KlJlqZPmM7lYNbdAQoJIabd cWWpIw=&downloadAs=winzip20-wz.exe&c=g1X/4RPaXiS4ZiM/Rwpme otUr2CmJb4S WPqtErCd/.../sXcTMidVtKUZ3FvVaD0PSomR93By6BOZN8CIs3F

http://www.winzipdownloadfiles.com/c?fallback_url=http://download.winzip.com/gl/nkln/winzip20_downwz.exe&x=Te/.../kJa3LHM DyvPXVp8te9uXHh72Qt BpZqI15EH37uNh3MIAVCO5BepaliwDCHTaXzkZxfTxWld5HqzITln5lwXjKghjkK9QdWJLBARjGry5Htajve

http://www.winzipdownloadfiles.com/c?fallback_url=http://download.winzip.com/gl/nkln/winzip20_downwz.exe&x=dElUX5ziu1oMizgOXsiQnMoPwD2XtnZEOwV2G AgC8E=&downloadAs=winzip20-wz.exe&c=8upkbQsCUrXZ2TJdFp6d1Yn75e/hRSmtpOCRGKWUyffGJuXqAaaOFshi/dBKYEu/.../UQIDoDKxz80AUj00oIwXeZlaFFkAqFQFBJOYyc3uOPWesIs8v

http://www.winzipdownloadfiles.com/c?fallback_url=http://download.winzip.com/gl/.../winzip20_downwz.exe&x=0VDSOVUX7JSuZ529qyFmg9XBGVcfy8UxB1AfQnBl4Ys=&downloadAs=winzip20-wz.exe&c=wbF5yR7zOz9vk6kfFXoklBYGlWa2ay3B6uf8UC5hW4HeRXOIdp2Cf3V cIbbB43cfs5rbiGSpTGisnaJCL2wNdluLZZ5Jzo2JVr4WAO52auT5 HHmWuDT60a1VYkv5Gm

http://www.winzipdownloadfiles.com/c?fallback_url=http://download.winzip.com/gl/nkln/winzip20_downwz.exe&x=A7Tfm8tJxJ2warSVKRzdTUVc e6oOO4Qfs6h0P0xAK4=&downloadAs=winzip20-wz.exe&c= G13CHjVAyq3FFoW0FSfpdy bblhHGvRBKWeSoRYFa3QJQYH zrAhlC/UF/5VwpEIBeFjKW2FLMqsNLcPUzOeQENzeXZW/.../jjpFXwqgFRVsAHj2 l4b1MGrKp

http://www.winzipdownloadfiles.com/c?fallback_url=http://download.winzip.com/gl/nkln/winzip20_downwz.exe&x=VC1yyp/zM/OjjXR4/0OfGYtbQc5/Kqi3XCsHe45zmmA=&downloadAs=winzip20-wz.exe&c=dlfsOOu49DBiKKsBT8OLq/Ehxltq2Mrll1es3CGKlaDqH36QFayQfL5u7ijqUne1RyiNMviBgxXY5LaSP5I0jxkLCR/.../Lju7x2DwVVB3hdLspoX434

http://www.winzipdownloadfiles.com/c?fallback_url=http://download.winzip.com/gl/nkln/winzip20_downwz.exe&x=mdUfgrkcFIhQGuY Rna1myozsjwFTWwkB4p/k9cqkqs=&downloadAs=winzip20-wz.exe&c=QyHiqZ/eZjcgwKZ/X I2beRJdSM9BwgsF9diKrf48DXGXDUqdRgwgA/3asLoW0KIeGFOI8M8zltZJbI2Ur52RE4NXqY3/.../HsSaA1cd8iFylUJ7MkfmXvgNUaVmCJJT9

Latest 30 of 43 download URLs

Scan winzip20-wz.exe - Powered by Reason Core Security