earpro5setup.exe

EarMaster Pro

EarMaster ApS

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
EarMaster ApS   (signed by EarMaster ApS)

Product:
EarMaster Pro

Description:
EarMaster Pro Setup

Version:
5.0.0.625

MD5:
4a8213e4d9a7ac540d05b7139d980ee2

SHA-1:
f1755c8c527b69ee8405aa7371142a9a5271f251

SHA-256:
3c0a49709bc0a8d6d9a3e368aa6bbd1dcf09e10684cea982e658f3afab69fbdc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/4/2024 7:10:43 PM UTC  (today)

File size:
4.6 MB (4,839,192 bytes)

Product version:
5.0.0.625

Copyright:
Copyright © 1996-2010 EarMaster, Denmark

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/6/2010 1:00:00 AM

Valid to:
8/26/2012 12:59:59 AM

Subject:
CN=EarMaster ApS, OU=SECURE APPLICATION DEVELOPMENT, O=EarMaster ApS, L=Egaa, S=Aarhus, C=DK

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
6B554B8C83F58FBC0267DBB2AA19D8F6

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:dqPYisjX1/sDIrGJL/a1i2WuUCWi4qJ5vwjbAXh:Is9skCJL69Uk7J5YYXh

Entry address:
0x9B24

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, A2, 95, FF, FF, E8, A9, A7, FF, FF, E8, D4, C9, FF, FF, E8, 1B, CA, FF, FF, E8, 0E, F3, FF, FF, E8, 75, F4, FF, FF, 33, C0, 55, 68, DB, A1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, A4, A1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 02, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 04, D0, FF, FF, 8B, 55, F0, B8, EC, CD, 40, 00, E8, 53, 96, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, EC, CD, 40, 00, B2, 01, B8...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file earpro5setup.exe has been seen being distributed by the following 17 URLs.

http://gsf-cf.softonic.com/f17/55c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=225868&instance=softonic_br&type=PROGRAM&Expires=1425433687&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=FS7jOHlSRp1gsMMLENLmDnzcokKoHUpo~zBaxakVnoZAlJEJibHGKmdbo-fHIs-XiT8yVMhj8GBZL5hM2Tpm7Ugm4ELy1Uoy6yyoHR98Ooyt0m0HS8zNOpFZAn6gpdfuywA1KaAhbcuELXgTSAwJteJBimD739PdTCBJIGOX2nQ_&filename=Earpro5setup.exe

http://gsf-cf.softonic.com/f17/55c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=225868&instance=softonic_es&type=PROGRAM&Expires=1448696648&Signature=EzSVFYvfF~yLUZ~73YXnthxiMaSe3J-BsDyfH95HU5QjuFuEVUDWxtYk0YNm9~VWaE-VD5pu82sHlHPK8xR1yC153h6GSs4RE3CCn~ie8vLANNcQa08pA5FEn2n~f7hY5bEfyTi9qdxgi4tQ4XRHoNLeThv9GPc7lKc-kTePTZc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Earpro5setup.exe

http://gsf-cf.softonic.com/f17/55c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=225868&instance=softonic_br&type=PROGRAM&Expires=1482730614&Signature=VnAYVGMAPKKYdBsGiVGRI30rbUi0WjVZtXFgQoHJTKgdb8znsIRXSeDCDhym2azYhH146Nn86NOA0EDKE31-Tr4uD8y4NamzpKHrxOUjBw-pLr2WVGUba~FnGyeOxy0BowxXcOa-IbSfH5jo~MhX3BUpFF4Yu2YGZNMVWYQB4UQ_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Earpro5setup.exe

http://gsf-cf.softonic.com/f17/55c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=225868&instance=softonic_es&type=PROGRAM&Expires=1446103478&Signature=hGu59JJe-ufcpnn~9sG35430DiR15m7dJgA7DrBjt8T3xrGKKX6ew8xKWwt852KNcRJG7-kzwbnm64Rr6K52Rkg9H7QtfxqAZrQ33~ZYcqAoaAl1Nm5egJ3mPPkXs-m4xblDWb7sySNAAOYgy2jV5daYWtIBx1roCX9MCshYW1M_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Earpro5setup.exe

http://gsf-cf.softonic.com/f17/55c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=225868&instance=softonic_es&type=PROGRAM&Expires=1477993217&Signature=O~~koiRP-MmrEvFESoD71xHtcFu3bK4je31pPYiwHijRPKj1GekOLThGqkRNe3GAzKTIzBlyKuB4Q4RBAm7uEupJAhA5Vav53jjZJgDftPQ0Pyv62EZtmxjFktwz6GwkPBT45UOPxLzRr6VhdOoQdrIL3YMkyrhu2B8KvtxXua8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Earpro5setup.exe

http://gsf-cf.softonic.com/f17/55c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=225868&instance=softonic_es&type=PROGRAM&Expires=1474606949&Signature=LCDCIyr0pfJd-sOUf1cbtRZVXgAXSP92upLYt~ECrDPTIzUtuE5FOz9saWTyJrPCWfgbq7Bwv24Df0CRt~ZWaifeLc125ueXUNqnvIedgJp-qhatgSa~IwLiuEN6ZclzAzkH0HcGVVm0ZpLrltIjLLjk-C9~X9SIlAiF1hzjkb0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Earpro5setup.exe

http://gsf-cf.softonic.com/f17/55c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=225868&instance=softonic_es&type=PROGRAM&Expires=1426677154&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=WQfe-GIJSwHytaBs9vpakXuxiEryrQmjxreWg0VQrrxFWHUGBntN~2uflJbsZNQhM9qJOs7ZsSXzW5M~LQwVtqvgb-VaUPK98sY8h5L7gCZWdS3Rgodw1Z6E06XN3mSWsQUih388rw2sYnp1qXFJ2ltP6~hapJ8Zx4kn-Q3S8Rw_&filename=Earpro5setup.exe

http://gsf-cf.softonic.com/f17/55c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=225868&instance=softonic_es&type=PROGRAM&Expires=1457519987&Signature=KBlF5iBmNrIEHEIqO3XziyUPqSY5A0ln4QBJlFu7qcPQHk5-6cJdRIyfz3luPzjci3WMHfeFrHXIJHxSoOGeJI170f~NEN2frqLJhsLpW7T65p13~S~2bJLFyng9cXd5Uw-FtG3LzNCxlAPgxGfUgT32CHfbqwWsNtSrkUfPb24_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Earpro5setup.exe

Scan earpro5setup.exe - Powered by Reason Core Security