EvercontactSetup.exe

Evercontact

Kwaga

This is a setup and installation application. The file has been seen being downloaded from www.evercontact.com.
Publisher:
Evercontact by Kwaga  (signed by Kwaga)

Product:
Evercontact

Description:
Evercontact for Outlook

Version:
2.7.6

MD5:
f389befb5e0508eb3cfaa873caad03ac

SHA-1:
71a989f13d4b0517f08bffb4e91534d6123955f6

SHA-256:
6ee75faebc99357008352bc4a4f3c00d0dc916366045d05464c256e3278967bc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/15/2024 6:12:36 PM UTC  (today)

File size:
12.6 MB (13,167,952 bytes)

Product version:
2.7.6

Copyright:
Copyright (C) 2014 Evercontact by Kwaga

Original file name:
EvercontactSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\evercontactsetup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
7/16/2013 2:00:00 AM

Valid to:
11/14/2016 1:00:00 PM

Subject:
CN=Kwaga, O=Kwaga, L=Vanves, S=Ile-de-France, C=FR

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0BFB54D7395F7850B76D836459A8DD99

File PE Metadata
Compilation timestamp:
4/28/2014 9:48:39 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:8AQZ7qcxcuGBqfutY6K+aD9elpia+RnXT1OfoY7E77XpXoEpO2WdpXy8xB0/NMLB:O7qwvDMlpi9DXoEYXyknB

Entry address:
0x31A3E

Entry point:
E8, B9, 9F, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 04, 8B, 4C, 24, 08, F7, C2, 03, 00, 00, 00, 75, 3C, 8B, 02, 3A, 01, 75, 2E, 0A, C0, 74, 26, 3A, 61, 01, 75, 25, 0A, E4, 74, 1D, C1, E8, 10, 3A, 41, 02, 75, 19, 0A, C0, 74, 11, 3A, 61, 03, 75, 10, 83, C1, 04, 83, C2, 04, 0A, E4, 75, D2, 8B, FF, 33, C0, C3, 90, 1B, C0, D1, E0, 83, C0, 01, C3, F7, C2, 01, 00, 00, 00, 74, 18, 8A, 02, 83, C2, 01, 3A, 01, 75, E7, 83, C1, 01, 0A, C0, 74, DC, F7, C2, 02, 00, 00, 00, 74, A4, 66, 8B...
 
[+]

Code size:
278 KB (284,672 bytes)

The file EvercontactSetup.exe has been seen being distributed by the following URL.

Scan EvercontactSetup.exe - Powered by Reason Core Security