freeofficewindows.exe

SoftMaker FreeOffice

SoftMaker Software GmbH

This is a setup and installation application. The file has been seen being downloaded from telechargement2.pcastuces.com and multiple other hosts.
Publisher:
SoftMaker Software GmbH  (signed and verified)

Product:
SoftMaker FreeOffice

Description:
SoftMaker FreeOffice Setup

Version:
1.0.0.3515

MD5:
704665788245103904ec281cb0535d70

SHA-1:
7a80d0c41cb569bce0f32e71433404be92dd2a98

SHA-256:
66746132f4b101d1a9ea2901cd9f7b2a90e95ef8912d389815cef75f3d8c40f3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 3:29:07 AM UTC  (today)

File size:
58.7 MB (61,519,584 bytes)

Product version:
1.0.0.3515

Trademarks:
All Rights Reserved

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\freeofficewindows.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
6/29/2015 8:00:00 PM

Valid to:
9/20/2017 7:59:59 PM

Subject:
CN=SoftMaker Software GmbH, O=SoftMaker Software GmbH, L=Nuernberg, S=Bayern, C=DE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
4BACCE6A5B02979FAE0CC30D5FEC52F9

File PE Metadata
Compilation timestamp:
11/30/2015 8:55:46 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1572864:ySKyZcWMV+gD4sH3jdLwYk8Hh5aWjIMF5yi1QZ:ymZcLcgDBhLnk2DynZ

Entry address:
0x7DCF0

Entry point:
E8, C3, CB, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 14, 37, 4F, 00, 75, 02, F3, C3, E9, 45, CC, 00, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, 51, E8, AD, CD, 00, 00, 59, 59, 5D, C2, 04, 00, 8B, FF, 51, C7, 01, CC, 9C, 4C, 00, E8, 29, CD, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 55, B5, FC, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, 51, E8, 00, CF, 00, 00, 59, 59, 5D, C2, 04, 00, 8B, FF, 51, E8, 4F, CE, 00, 00, 59, C3, 8B, FF, 55, 8B...
 
[+]

Entropy:
7.9967  (probably packed)

Code size:
767.5 KB (785,920 bytes)

The file freeofficewindows.exe has been seen being distributed by the following 4 URLs.

http://telechargement2.pcastuces.com/temp6bs2/.../freeofficewindows.exe

Scan freeofficewindows.exe - Powered by Reason Core Security