hawkeninstaller.exe

Meteor Entertainment, Inc.

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with Hawken. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Meteor Entertainment, Inc.  (signed and verified)

MD5:
fdf230c76c331dff043aedc9547f3e93

SHA-1:
e4349bbeb5237dee9c06d4ac8c856be821f19848

SHA-256:
4fb61779c4d0d30db658a88ebba764151e5bbe92705c07a5c268efd18fde1ef6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:17:24 PM UTC  (today)

File size:
17 MB (17,857,464 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\hawkeninstaller.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
7/24/2012 4:28:27 PM

Valid to:
7/12/2015 7:33:41 PM

Subject:
CN="Meteor Entertainment, Inc.", O="Meteor Entertainment, Inc.", L=Seattle, S=WA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4F0C2CA0D294A2

File PE Metadata
Compilation timestamp:
12/5/2009 6:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:FRfTeeWl2/vHih3bkMAly1oO1bWTmSlEhv+TIhKF+sz0HrOVm6R6CujviqoCRC:FRfTzWM/vHa3gMAlgo1lYv+82QahryL0

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9730

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file hawkeninstaller.exe has been discovered within the following program.

Hawken  by Meteor Entertainment
About 1% of users remove it
 
Powered by Should I Remove It?

The file hawkeninstaller.exe has been seen being distributed by the following 8 URLs.

http://gsf-cf.softonic.com/e43/49b/.../file?SD_used=0&channel=WEB&fdh=no&id_file=6655854&instance=softonic_es&type=PROGRAM&Expires=1440208441&Signature=M6fhGOWWf1EjNDYoeuUIJP6eRjkl3VRuLpLQuUVOa-NJovmCZYmlKS4fADUorH3I2Z8vxexmLPW6FLnCGoH9Fa~SqiA76RbiKLZ1ikFqjNZwR4GyUza2Ukd8OkCqActVDNb-VEJmsDHYhZ~V2kVXSe5j8F8B1xZ93LHZ9d-XZxs_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=HawkenInstaller.exe

http://gsf-cf.softonic.com/e43/49b/.../file?SD_used=0&channel=WEB&fdh=no&id_file=6655854&instance=softonic_fr&type=PROGRAM&Expires=1472394101&Signature=ZIShH7YWLcfoP8Ar-JBsUZhYdOyglpI2zJlRETTR9KIn7c0M~EgbkNzl4F3rRPoeTWkfMdkb3UoL5r7wOLTLM9PSo6DtWW8QMFbZuI8psLr0VGCqNAyuSe7GW1NawSIyxkPcbJcGB~2-YsZelAu7VlqOUycJrcmONotAXP3uFIQ_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=HawkenInstaller.exe

http://gsf-cf.softonic.com/e43/49b/.../file?SD_used=0&channel=WEB&fdh=no&id_file=6655854&instance=softonic_br&type=PROGRAM&Expires=1472388887&Signature=GzZixSQb-CnVW3O2k9mSLD1HgShhgYpd3WF8tTGRg~1V2eAGvCLzPK1IL9sFCch8SVLe1Xy1y0stWOSjwo1cQ~KD8SOy0RNsi688IddqmNwaZyzD5xvxnFi8BgB5LvtmjGwMW-zBaJ8TXiNNvzIofkZp3n87Ptf~Z0Vouv01qtg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=HawkenInstaller.exe

http://gsf-cf.softonic.com/e43/49b/.../file?SD_used=0&channel=WEB&fdh=no&id_file=6655854&instance=softonic_fr&type=PROGRAM&Expires=1470529346&Signature=JhHygaotF7n3RqgNVIar2bQ0MHNB-V4vQWLUJNrsIQpqM98Pup1aNPTW4rTNaf8FINkTfj1IkzuavFFfAOMeswQMNZbUNJYzTmwJLLWzKNP3tV~07FU8rLXqBJQY6Lcz2T3~NK4ZwK-d7yG-FZ-xdeBIje1RcvCRvWpyDSWEPD8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=HawkenInstaller.exe

Scan hawkeninstaller.exe - Powered by Reason Core Security