frostwire-5.7.7.windows.exe

FrostWire 5

Frostwire, LLC

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from filehippo.com and multiple other hosts.
Publisher:
FrostWire LLC  (signed by Frostwire, LLC)

Product:
FrostWire 5

Description:
FrostWire - Search, Download, Play, Share.

Version:
5.7.7.1

MD5:
ac66812e9176ec53f230aef1f85af2db

SHA-1:
d261482937fd7031e01a2e9f414496e2b3f9e6e0

SHA-256:
bed430150655ea29af777f03c0cd42ba2aa8653b7e4e47ccd537e744f3f8b28a

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/19/2024 7:36:49 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.1417
9.0.1.0276

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant)
8.10505

File size:
23.1 MB (24,227,744 bytes)

Product version:
5.7.7.1

Copyright:
FrostWire LLC 2008

Original file name:
frostwire-5.7.7.windows.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\frostwire-5.7.7.windows.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/21/2014 9:00:00 PM

Valid to:
3/23/2016 8:59:59 PM

Subject:
CN="Frostwire, LLC", O="Frostwire, LLC", L=Miami Beach, S=Florida, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
35DE9D3C616713150858F57D7419F0D6

File PE Metadata
Compilation timestamp:
7/8/2012 8:50:55 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:DQBSVJFxtxsXYf1/hT9nwBYgsyDKSdkJWoIMtxzC5IlCGSKI/8OAKv4Op2pKRsjH:DQBSVJnAYfZhT9nwpvWSd2zz3LSK2vah

Entry address:
0x3A02

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, F0, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 38, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 34, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 1C, 93, 40, 00, 68, C0, AD, 46, 00, E8, 1A, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 08, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file frostwire-5.7.7.windows.exe has been seen being distributed by the following 28 URLs.

http://filehippo.com/download/file/.../

http://global-shared-files-l3.softonic.com/d26/148/.../file?nvb=20141229235856&nva=20141230115956&token=079b8203cccf08e8033c9&SD_used=0&channel=WEB&fdh=no&id_file=45854&instance=softonic_en&type=PROGRAM&filename=frostwire-5-7-7-windows.exe

http://global-shared-files-l3.softonic.com/d26/148/.../file?nvb=20141201215345&nva=20141202095445&token=0de2a9812ec588432026c&instance=softonic_en&filename=frostwire-5-7-7-windows.exe

http://www.techtudo.com.br/_/software/.../download

http://safe.pre-cloud.com:8080/safed.php?q=http://dl.frostwire.com/frostwire/.../frostwire-5.7.7.windows.exe

http://filehippo.com/download/file/.../

http://global-shared-files-l3.softonic.com/d26/148/.../file?nvb=20141204220440&nva=20141205100540&token=096cdf502a3dfea855e85&SD_used=0&channel=WEB&fdh=no&id_file=45854&instance=softonic_en&type=PROGRAM&filename=frostwire-5-7-7-windows.exe

http://filehippo.com/download/file/.../

http://global-shared-files-l3.softonic.com/d26/148/.../file?nvb=20141214143843&nva=20141215023943&token=09dd0f255269c9bc458ab&SD_used=0&channel=WEB&fdh=no&id_file=45854&instance=softonic_es&type=PROGRAM&filename=frostwire-5-7-7-windows.exe

http://download.oldapps.com/.../frostwire-5.7.7.windows.exe

http://frostwire-win.he.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-flqKOo6OolZk=

http://global-shared-files-l3.softonic.com/d26/148/.../file?nvb=20141129185222&nva=20141130065322&token=0132f2b39540b82b6e1c3&instance=softonic_en&filename=frostwire-5-7-7-windows.exe

http://dw.en.uptodown.com/dl/1447380206/.../frostwire-5-7-7-multi-win.exe

https://dw.uptodown.com/dwn/LQ3pO59xU3So-S-Vo1DhAhUTejXutDTwFiHvM5i8SiurfMvV_RT7_srw9bt1T_IIbwLz96r5SdOW4Gzik0pkn_03PCDrhfq419-lLCVZRBAz_m6wWmpAUTZiC5yxFOsn/Ivt2hETAzFRXFhKjqY7UrlinhWC7J4hPQCLAQWPxyvmXC3y_doAXfAG7a4GdTjENpn0mM301alFngaETihSOyaPocBD1iijc-j52fMbOuj7fPo74_q4Y7KhwZEqi743v/StjMjykbzTmma_oS8vFSpfhraOejQ19um6NVZv1N9lQye99RfPou4K423ObceAAqrbQvTcp85UMy7SF-5N-aOyy5Bm80PvRnANp1-ahMTApC-joe8G8OMm7zrveidbFc/.../

http://www.filehorse.com/download/file/.../

http://global-shared-files-l3.softonic.com/d26/148/.../file?nvb=20150120131818&nva=20150121011918&token=0b0f9bfbfad4170713af8&SD_used=0&channel=WEB&fdh=no&id_file=45854&instance=softonic_en&type=PROGRAM&filename=frostwire-5-7-7-windows.exe

http://www.filehorse.com/download/file/.../

http://global-shared-files-l3.softonic.com/d26/148/.../file?nvb=20150123205656&nva=20150124085756&token=030d1dbd414ea56f0244b&SD_used=0&channel=WEB&fdh=no&id_file=45854&instance=softonic_en&type=PROGRAM&filename=frostwire-5-7-7-windows.exe

http://global-shared-files-l3.softonic.com/d26/148/.../file?nvb=20150124123310&nva=20150125003410&token=03301904f6ffa1819ff77&SD_used=0&channel=WEB&fdh=no&id_file=45854&instance=softonic_en&type=PROGRAM&filename=frostwire-5-7-7-windows.exe

Scan frostwire-5.7.7.windows.exe - Powered by Reason Core Security