gsacinstaller_3_3.exe

Arabic Calligrapher 3.0 Release 3

Rami Kanhouche

This is a self-extracting archive and installer. The file has been seen being downloaded from lb.cdn.m6web.fr and multiple other hosts.
Publisher:
HemlockSoft, www.hemlocksoft.com  (signed by Rami Kanhouche)

Product:
Arabic Calligrapher 3.0 Release 3

Description:
Installer for Arabic Calligrapher 3.0 Release 3

Version:
3.0.3.0

MD5:
2f92ab9b0e510bd5a0683f6df6338428

SHA-1:
ef7b19077c441ea6cb18717918224a740cd57509

SHA-256:
e72e9938987f622ecc84740ac8a46deb8685879e436b0690182ebdf24b9cc7ba

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/22/2024 12:17:02 AM UTC  (today)

File size:
46.2 MB (48,495,768 bytes)

Product version:
3.0.3.0

Copyright:
Copyright (C) 2016

Original file name:
GSInstaller.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\downloads\gsacinstaller_3_3.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
7/15/2014 8:00:00 AM

Valid to:
7/20/2015 8:00:00 PM

Subject:
CN=Rami Kanhouche, O=Rami Kanhouche, L=Beirut, S=Beyrouth, C=LB

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0FC9212EAA16561C29D6B4B42DA17A15

File PE Metadata
Compilation timestamp:
6/11/2016 8:04:30 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
786432:tzai3pUp+FHfxfuSydGruUs1ELHT/LCN9u0Cblli/SKdIpw36EHgoN8WstJ9QAU9:tzaiGp+RZWlGr+1mr2N9u0Cbllird95L

Entry address:
0x1092F5

Entry point:
E8, F7, BF, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 30, E5, 57, 00, 00, 75, 18, E8, C0, B9, 00, 00, 6A, 1E, E8, 0A, B8, 00, 00, 68, FF, 00, 00, 00, E8, CF, 05, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 30, E5, 57, 00, FF, 15, D8, D2, 52, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, 38, E5, 57, 00, 74, 0D, 53, E8, 3A, C0, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, BD, 04, 00, 00, 89, 30, E8, B6, 04, 00, 00, 89...
 
[+]

Entropy:
7.9711  (probably packed)

Code size:
1.2 MB (1,226,752 bytes)

The file gsacinstaller_3_3.exe has been seen being distributed by the following 16 URLs.

http://lb.cdn.m6web.fr/d/c/a/765a5a65bd3734f5b5d5244a79cc5c00/58a035eb/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://lb.cdn.m6web.fr/d/c/a/4e7779ccad4050db24db297e0865f42f/58873923/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://lb.cdn.m6web.fr/d/c/a/438cd17b226e4c9a7e77a0584ac5e380/584c43e9/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://lb.cdn.m6web.fr/d/c/a/54978dbd391ffb2ad140cc70e0d8630f/58468cca/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://lb.cdn.m6web.fr/d/c/a/56fc8ce017e564f225affa56b3ece94d/5846a03f/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://lb.cdn.m6web.fr/d/c/a/0946ad37deb30d2905cd72ddb519ef47/57e004ac/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://lb.cdn.m6web.fr/d/c/a/92c748d05f6bdc088f2737f86c855589/57f385a6/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://lb.cdn.m6web.fr/d/c/a/2b76f33e6a6b75509c31f3dfccb18617/582efda3/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://lb.cdn.m6web.fr/d/c/a/55025d3941c3e175c75dc062c0f239d2/57fbfc5c/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://lb.cdn.m6web.fr/d/c/a/9ca9cbe3acf5606e46cc4688b613ba54/583a93f0/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://lb.cdn.m6web.fr/d/c/a/fd40a60705a045b3af32b93069f8b3dd/57f4c2c7/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://www.logitheque.com/.../258dadec.dl

http://files.downloadnow.com/s/software/15/28/64/.../GSACInstaller_3_3.exe

http://lb.cdn.m6web.fr/d/c/a/bc5655bc81384d58243e62262585c2dd/57d2d751/soft/.../arabic-calligrapher_3-0_en_122300.exe

http://lb.cdn.m6web.fr/d/c/a/c735be2c992e1cce881b97649e0d30a6/579cbbd0/soft/.../arabic-calligrapher_3-0_en_122300.exe

Scan gsacinstaller_3_3.exe - Powered by Reason Core Security