ywriter5full.exe

yWriter5

Spacejock Software

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Spacejock Software

Product:
yWriter5

Description:
yWriter5 Setup

MD5:
2440201750f65f38e64039f5d5ed4bb2

SHA-1:
a42829e947a5969575ab79ca7f43f5cd6dc2de32

SHA-256:
99c5ca20e6f40079ca14b4148395c8c17b385c054dcbb13393eb2bd9887bb1f8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 8:24:47 PM UTC  (today)

File size:
2 MB (2,046,840 bytes)

Copyright:
Copyright © 2001-2011 Spacejock Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ywriter5full.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:5aRyJJvIsIfUadfGqOwj3AZeCzQU5FwHK6vZG9cxOf3z5:QRyJqPvpzMXMguHK6vk95f1

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Entropy:
7.9942

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file ywriter5full.exe has been seen being distributed by the following 21 URLs.

http://gsf-cf.softonic.com/a42/829/.../file?SD_used=0&channel=WEB&fdh=no&id_file=41650&instance=softonic_es&type=PROGRAM&Expires=1429872655&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=UwUbmpdsO2Oudek48A~pV2mpDJxGdNH5U-tqDRI3mT2lrtQhwy4O4qPv3sVBzbfWbn7AlwWE2jQU4UxXSJEDsgJZEhPGe7hcYgF0nI0iM2iuC0I4j53gvWWEBGBrELn~0UAkR7nrtcKaihxBzCKvG85LZStIWFDuS3A0JStum~I_&filename=yWriter5Full.exe

http://gsf-cf.softonic.com/a42/829/.../file?SD_used=0&channel=WEB&fdh=no&id_file=41650&instance=softonic_es&type=PROGRAM&Expires=1475748494&Signature=fggi~UHnsulQaSTnxCKxsSnOVBUgdLyk7V~IgnQKhOnFVder63~APwp9hyc7JTxRulJidWJtEj72OdqEDZPT0QloSj-r6xI-9AmAhEEj0aSc2leqvET1jUrc26~ew3lCHLmUq334z3m7rUjdQA8eouQaTsHKxu9~tcXa9op6ulU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=yWriter5Full.exe

http://gsf-cf.softonic.com/a42/829/.../file?SD_used=0&channel=WEB&fdh=no&id_file=41650&instance=softonic_es&type=PROGRAM&Expires=1444660900&Signature=eIRei19fBJoOFTYOJ~JvYXGb7lt16owB3x205Ca~TfuCNu98L04WoVOFI7E~6SaBVYZQOqCbzULIPqQnIh1Lwrov~PBnynhHBXzarp0kWq~-2G5xd3PVbuw9HBmPI-lnE4PBZoiRxF9Jv5QTbQ6D8pYRrWRBZw7v6425gr972VE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=yWriter5Full.exe

http://gsf-cf.softonic.com/a42/829/.../file?SD_used=0&channel=WEB&fdh=no&id_file=41650&instance=softonic_es&type=PROGRAM&Expires=1469700210&Signature=PVfzqFuaHw1y0lClaUzN-sYGMXvjcmgwVugH9qFQNoq~cvuG9NyW8OYZa6qrMfe~OqzRGoetFecA27OyHnE5sdBhtSQ290mZExsJgVcemV3pIpBkz7ygVc41hKGUrGiTVm-15fQQVHZopvHftq1e987Av6dWrjbNP0LPewgXkFY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=yWriter5Full.exe

http://gsf-cf.softonic.com/a42/829/.../file?SD_used=0&channel=WEB&fdh=no&id_file=41650&instance=softonic_fr&type=PROGRAM&Expires=1479872951&Signature=H-7EAoZz3X4nnrGauRf-fpoySnvNfQQdLfq8zYSTmrGgZf8V3nJP7Q5BgrMNhuOY7u-g05VslKZ4eDpK8hml7qvOWyARb8Wian2MC7bPEgGRW2j3t9HG2jbbIXL6HsF6QKikAoNryfPSREkXk0LAtf6oNvZYGVcq0YQCSBkmeIw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=yWriter5Full.exe

http://gsf-cf.softonic.com/a42/829/.../file?SD_used=0&channel=WEB&fdh=no&id_file=41650&instance=softonic_es&type=PROGRAM&Expires=1434474606&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=WJ6HXHVgtd0grKYNzvqlnc4x3gO-Y2mu~4Hif2P71pziIa-op-Ur2CQazOx5EJFbDAb~7UbFkmIZ37qdZh7jYGDyVCjgtD22b9mlzYwioPM-1oeWwq1tXvsLmcLYvtcVgmQ15~LLK2Usa0jBprYgrpVij4~LY4Kxoh-w7u3ZP8s_&filename=yWriter5Full.exe

Scan ywriter5full.exe - Powered by Reason Core Security