xara_web_designer_12_premium_dlv_content_en-gb_160329_12-13.exe

Content Pack (en-GB)

Xara Group Ltd

This is a setup program which is used to install the application. The file has been seen being downloaded from dl05.magix.net.
Publisher:
Xara Group Ltd  (signed and verified)

Product:
Content Pack (en-GB)

Version:
1.0.0.0

MD5:
7aa400e9507e88ff749ae3de377a5677

SHA-1:
17221adb1d92c03e2574b42a1f9689ad82daf694

SHA-256:
73e2024c0ce6f0b6931261924a0f306b20c40434788ad9310c8745e45dbab1a1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 5:55:30 AM UTC  (today)

File size:
45.7 MB (47,882,360 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Xara Group Ltd

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\xara_web_designer_12_premium_dlv_content_en-gb_160329_12-13.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
9/17/2015 7:00:00 PM

Valid to:
9/17/2016 6:59:59 PM

Subject:
CN=Xara Group Ltd, OU=SECURE APPLICATION DEVELOPMENT, O=Xara Group Ltd, L=Hemel Hempstead, S=Herts, C=GB

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
63A4A6470C1B5EAFE82BD3DC5627180C

File PE Metadata
Compilation timestamp:
1/6/2016 8:49:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
786432:NS6kTCJ/IFSvkY/NaFgZ+WJFEenjCVwnEthdBKhQG0nyEzgeMsd3Jo7bsFju3:aTCJ/UU9lRtJFvnjEthd4hQGuyRshGGQ

Entry address:
0x4DF50

Entry point:
E8, EE, 8A, 00, 00, E9, 7F, FE, FF, FF, FF, 35, CC, C1, 4B, 00, FF, 15, 4C, C2, 48, 00, 85, C0, 74, 02, FF, D0, 6A, 01, 6A, 00, E8, 50, 90, 00, 00, 59, 59, E9, 68, 90, 00, 00, 55, 8B, EC, 53, 8B, 5D, 10, 8B, C3, 56, 83, E8, 00, 0F, 84, DD, 16, 00, 00, 48, 0F, 84, C5, 16, 00, 00, 48, 0F, 84, 8F, 16, 00, 00, 48, 0F, 84, 3E, 16, 00, 00, 8B, 55, 0C, 48, 0F, 84, AC, 15, 00, 00, 8B, 75, 08, 57, 83, FB, 20, 0F, 82, A1, 04, 00, 00, 8B, 06, 3B, 02, 0F, 84, 80, 00, 00, 00, 0F, B6, F8, 0F, B6, 02, 2B, F8, 74, 16, 33...
 
[+]

Entropy:
7.9917  (probably packed)

Code size:
555 KB (568,320 bytes)

The file xara_web_designer_12_premium_dlv_content_en-gb_160329_12-13.exe has been seen being distributed by the following URL.

http://dl05.magix.net//2016/.../Xara_Web_Designer_12_Premium_DLV_content_en-GB_160329_12-13.exe