wunderlist-setup.exe

6 Wunderkinder GmbH

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from t.wunderlist.com and multiple other hosts.
Publisher:
6 Wunderkinder GmbH  (signed and verified)

MD5:
6e258c2197e4d2f058defe6a1126c350

SHA-1:
cd1a3a1e00b1bbbc571684733320e71f0e70b3be

SHA-256:
57ee9fe435f28470344165edfaa402e4538dc27c2713825915ff2fe03c0eb6a4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 3:19:38 AM UTC  (today)

File size:
38.7 MB (40,617,552 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\wunderlist-setup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
1/8/2016 1:00:00 AM

Valid to:
2/7/2017 12:59:59 AM

Subject:
CN=6 Wunderkinder GmbH, O=6 Wunderkinder GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
36C84D4A1289E42DE51C84FAD2683E03

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:eceC/UeBG/A12dLsrOBBY9VVDZjJe9R+2qXKltW8J6SNTPRBQrVegSbFB+WHEBZA:edCMeUircByVXY9nzW8JPNMrktbL+GEk

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file wunderlist-setup.exe has been seen being distributed by the following 18 URLs.

https://t.wunderlist.com/.../CTQztOccF_rxFjUyNNEKBdqYy_aqxmMAAGRvd25sb60vd2luZG93czcAMhIzNDI2MQBvbmJvYXJkaW5nLXVzZXItc2lnbu0tdXAtQjFGMABkb3dubG-tX2xpc3Rfd2luZG93czc

http://www.ranchsendgift.com/tyRf2xU9v1R3nQ6GJjDGEtbZYywLz7ymiHDE3sBlWLCLhy2mjXIdeIL8jPl JnSV9fMI1Uvfb WS2SG4F5Ejh8fomdcKl8xLnIvjbPBiuTO02EZMPH4DP7c9zTWJKSlLLCyLt7lR6ngEqv7PjO9KqtJSaofQLyncqMKXaPdP0cUSurMFHB2TvFkNroSnri_YNAERch23nE3APpDKfik6GyTSpNtuSg==-G04AAETdFtN_xGAKBrNhoEWETS445ATw85YkGFPzYGPsLJdB2yzpXuKzGp4lKCu nmZSjSycmbK8wGDkPi0G6w696_gA

https://t.wunderlist.com/.../BBgPrjTCGjUz7zfXpraBBTQUNjPeko44AABkb3dubG-tL3dpbmRvd3M3ADIWATI0OABvbmJvYXJkaW5nLXVzZXItc2lnbu0tdXAtQjFGMABkb3dubG-tX2xpc3Rfd2luZG93czc

https://t.wunderlist.com/.../oTM1tjU3jjIyndi6sYUYCY62F9oF7aMAAGRvd25sb60vd2luZG93cwAyGZcWNQBwcm8tcHJvLXN1YnNjcmlwdGlvbi1jb25maXJtYXRpb24tQzRCOABmb290ZXJfd2luZG93cw

https://www.wunderlist.com/.../windows8

https://t.wunderlist.com/.../NZG6gKI1NOf8MqM0NiC37qcyNTM2NjczMzfiMwAAZG93bmxvrS93aW5kb3dzADIyMxaXNgBvbmJvYXJkaW5nLXVzZXItc2lnbu0tdXAtgTlGAGZvb3Rlcl93aW5kb3dz

https://t.wunderlist.com/.../NPMTMjQbNzO4NDayw870qa-CNjU3zjXr7zgAAGRvd25sb60vd2luZG93czcAMjQwBDU2OQBvbmJvYXJkaW5nLXVzZXItc2lnbu0tdXAtQjFGMABkb3dubG-tX2xpc3Rfd2luZG93czc

http://www.techspot.com/downloads/downloadnow/.../?evp=4513f167728d1364d6c4636ef93c7de6&file=1

http://www.towerbitscenter.com/co0cDeX5IAUHX90PnQ_jDcE rSWF66xNQZ9U3kKuzSUCPz7JiOb7 OmZ911aH_TGRTJIsHb7kicuBksL9DdIrVUH k5OXM8ik891p18iHhrLBD mrLXOns5snWusXPbVpjKwBhgTQMNKQ7YlTJkjuhrTOufXd4Tj0MnqK25irLPwhkdSxYB0FIp3Yj3KWStpS5rMxvsVTOnVVMChPuQtVOG3c3sxqw==-G04AAETdFtN_xGAKBrNhoEWETS445ATw85YkGFPzYGPsLJdB2yzpXuKzGp4lKCu nmZSjSycmbK8wGDkPi0G6w696_gA

https://t.wunderlist.com/.../Muk1HwrHNODQN9COMzIeoB029q01NYMyhwAAZG93bmxvrS93aW5kb3dzADI1CDY2NzMAbWFpbnRlbmFuzi1yZW1pbt5yLWR1ZS1EEUEAZm9vdGVyX3dpbmRvd3M

https://www.google.com/url?hl=en&q=https://t.wunderlist.com/.../NuQZq8LW178y9Jb82Yw1vYc30dAy72EAAGRvd25sb60vd2luZG93czcAMjQ1BZgxAG9uYm9hcmRpbmctdXNlci1zaWdu7S11cC1CMUYwAGRvd25sb61fbGlzdF93aW5kb3dzNw&source=gmail&ust=1469209050561000&usg=AFQjCNGyxBm2ji8fsuUPoUt8-RgA9Tl3oA

Scan wunderlist-setup.exe - Powered by Reason Core Security