hexels_install_253.exe

Marmoset LLC

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from s3.amazonaws.com.
Publisher:
Marmoset LLC  (signed and verified)

MD5:

SHA-1:
80c763c4d786628af76e8025101e15be829c5be3

SHA-256:
fdff028054004b74e6f21362aec1100e26686be21473b57e55fdd3edf43761f6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/2/2024 2:20:40 PM UTC  (today)

File size:
57.7 MB (60,492,424 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\hexels_install_253.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
10/26/2015 12:00:00 AM

Valid to:
11/8/2017 12:00:00 PM

Subject:
CN=Marmoset LLC, O=Marmoset LLC, L=Waterloo, S=Iowa, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
056D39CB1F7F5DCDEC951266830F84B5

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1572864:U1XXELym228NdbFr+Oj0+hpDsNYuNDWw9Em01U8Bh5VEMvvT00q+r:i/08NBxRTsNYun01jBhjEMvvzq+r

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9971

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Access Provider
Name:
MartaExtension


The file hexels_install_253.exe has been discovered within the following programs.

Adobe Reader X (10.1.5)  by Adobe Systems Incorporated
Adobe Acrobat X (version 10.0) is an applications designed to view, create, manipulate, print and manage files in Portable Document Format (PDF). Acrobat and Reader are widely used as a method of presenting information with a fixed layout similar to a paper publication.
www.adobe.com
4% remove it
Java 7 Update 13  by Oracle Corporation
This release includes important security fixes. Oracle strongly recommends that all Java SE 7 users upgrade to this release.
java.com
9% remove it
Java 7 Update 15  by Oracle Corporation
Publisher's description - “The full version string for this update release is 1.7.0_15-b03 (where "b" means "build") and the version number is 7u15. JDK 7u15 contains Olson time zone data version 2012i. For more information, refer to Timezone Data Versions in the JRE Software.”
www.oracle.com/technetwork/java/javase/7u15-relnotes-1907738.html
6% remove it
Java 7 Update 7  by Oracle Corporation
Publisher's description - “This releases brings in key security features and bug fixes. Oracle strongly recommends that all Java SE 7 users upgrade to this release. JavaFX 2.2.4 is now bundled with the JDK on Windows, Mac and Linux x86/x64.”
12% remove it
QuarkXPress  by Quark Inc.
www.quark.com
8% remove it
The Sims™ Life Stories  by Electronic Arts
The Sims Life Stories is a video game distributed through EA's Origin digital distribution and digital rights management content delivery system.
www.ea.com
5% remove it
Total Video Converter 3.71 100812  by EffectMatrix Inc.
Publisher's description - “E.M. Total Video Converter is a piece of extremely powerful and full-featured converter software that supports almost all video and audio formats.”
www.effectmatrix.com/total-video-converter
19% remove it
TVCenter  by PCTV Systems
Publisher's description - “PCTV TV Center is equipped with a powerful PVR functionality. You can watch your favorite TV stations, timeshift, schedule recordings and much more . PCTV TV products bring TV to your computer. You can easily enable your PC / Laptop with a full featured TV functionality.”
www.pctvsystems.com
23% remove it
 
Powered by Should I Remove It?

The file hexels_install_253.exe has been seen being distributed by the following URL.

http://s3.amazonaws.com/mset/download/.../hexels_install_253.exe

Scan hexels_install_253.exe - Powered by Reason Core Security