ZenMateSetup.exe

BrandedSetup

ZenGuard GmbH

This is a setup and installation application. The file has been seen being downloaded from en.softonic.com and multiple other hosts.
Publisher:
ZenGuard GmbH  (signed and verified)

Product:
BrandedSetup

Version:
1.0.0.0

MD5:
7c5597cebb0c3eb4abbb95561ca6804b

SHA-1:
b6769dadec20a105faffac40fd9c9ed18953f62e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/2/2024 3:38:48 PM UTC  (today)

File size:
936.5 KB (958,992 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2016

Original file name:
ZenMateSetup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
4/11/2016 1:00:00 AM

Valid to:
4/12/2018 12:59:59 AM

Subject:
CN=ZenGuard GmbH, O=ZenGuard GmbH, L=Berlin, S=Berlin, C=DE, SERIALNUMBER=HRB 151355, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.1=Berlin (Charlottenburg), OID.1.3.6.1.4.1.311.60.2.1.3=DE

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0685FDC5DC0CD7393C6AA955616F4C8C

File PE Metadata
Compilation timestamp:
4/22/2016 2:25:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:xhEf1kUIUUUU3UUUUU3UUaUUUevDmbUCUU4VaMKUeziUUlsU+U0CUUQUUU4ileU5:of1kUIUUUU3UUUUU3UUaUUUevDmbUCU3

Entry address:
0x8F2CA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
565 KB (578,560 bytes)

The file ZenMateSetup.exe has been seen being distributed by the following 19 URLs.

http://en.softonic.com/sads/tracker.php?ev=c&co=US&sid=b47139ecf03c9acb7064e00cdfcf490f&upv=2f85b49db4b2d28fab54ea9cae237999&z=results&sk=0&abp=0&params=F39B2A32BFC101987B1458170C278E032123FF0E09F5565AD6A3C9E074A2DA09277A9F2B702D8CF786D1BF90D7B59356BB3015B81110C70C2F98818A70F2C2319D0FAA267FF380E5931E3C3FE4B7F3605E953E25C103022479F1C0F64036CE53D9605870F899939350E72FED8B847A7C9DF13CBA97960040F1371A8E7A870276B958B50A3CBB179D8224ED6A7700426823205B6B759D822F44EA2F9A4598BC07A4BEC01D5091390D06B1D319F00999C6&h=65B358E3E5A034BA08DA8BE1DE062540E04B80FCB988CAE5B339D065A76689BF&directdownload=1&f=69716476&d=https://s3-eu-west-1.amazonaws.com/zenmate-windows-update/installer/.../ZenMateSetup.exe

http://en.softonic.com/sads/tracker.php?ev=c&co=GB&sid=44592997f7eb7042270981207b793cbd&upv=4da643ccac40a3b73deb4a018f3e3ddc&z=results&sk=0&abp=0&params=F39B2A32BFC101987B1458170C278E032123FF0E09F5565AD6A3C9E074A2DA09671002EB24956F76FC29EB1755A0BA5EF3F51A6269990587475D24C894B8A5CC85105064BFEF2E68388ED8D6B7EC876F07A6BE78FA8B211D510DA03A8E4CDD83E3D5E361CAC0FEDD7E4757376FDA5A43E30B7E15721636636488F91DBD753BDCD404DF761DD16BC0D9336E86AA50538AE6552F32BCC6CE77D8916B2A061033FF&h=5CAD0B0640F05EF0D9B1F1B4CA6D56FB460AF1B55BA4FC3AB3701E9789E014FD&directdownload=1&f=69716476&d=https://s3-eu-west-1.amazonaws.com/zenmate-windows-update/installer/.../ZenMateSetup.exe

http://zenmate-desktop-vpn.en.softonic.com/download

Scan ZenMateSetup.exe - Powered by Reason Core Security