hw32v601.exe

Hex Workshop v6

BreakPoint Software, Inc.

This is a setup and installation application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
BreakPoint Software  (signed by BreakPoint Software, Inc.)

Product:
Hex Workshop v6

Description:
Hex Workshop v6 Installer

Version:
6.0.1.4603

MD5:
89aa0f9efd78100daa96f9baf36da066

SHA-1:
524b3a9af796176822829eb3843056647d125239

SHA-256:
63203ab9fa2b6d026724fd3337d0230370b583854a3bacbed589fd9f2dc6b3af

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 11:47:23 AM UTC  (today)

File size:
10.2 MB (10,648,816 bytes)

Product version:
6.0.1.4603

Copyright:
Copyright (C) BreakPoint Software

Original file name:
hw32v6.0.1.4603.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
10/19/2007 2:00:00 AM

Valid to:
10/18/2009 1:59:59 AM

Subject:
CN="BreakPoint Software, Inc.", OU=SECURE APPLICATION DEVELOPMENT, O="BreakPoint Software, Inc.", L=Wayland, S=Massachusetts, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
333C4ACBC897F334E235FFB812152B20

File PE Metadata
Compilation timestamp:
12/8/2008 2:27:22 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:L94IcnA1Agg5j06f7iBrZU35ANFNB0S4qaNoFus9kVfr2:anA1A906fNEJ4h3suT2

Entry address:
0x1F7AF

Entry point:
E8, 0B, 6F, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, 68, 20, F8, 41, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 40, 50, 43, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73...
 
[+]

Code size:
178 KB (182,272 bytes)

The file hw32v601.exe has been seen being distributed by the following 5 URLs.

http://gsf-cf.softonic.com/524/b3a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=34508&instance=softonic_fr&type=PROGRAM&Expires=1480919618&Signature=HbFry3X-X2eMrYFbe0nIdhSB-YKKSClG6BozJc9THyeUlIwjOYji~x~wL~0T2uTZfJdOr3~uzQnpqCsOp4sT1HfxinNQD5nLuXGpeginlYVOBXqnCWOB7qIx2GQ7e3qlbThCEg7RmDeC3Z0So9RhlFdYqPjjr1D97KEgitpPMTo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=hw32v601.exe

http://gsf-cf.softonic.com/524/b3a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=34508&instance=softonic_es&type=PROGRAM&Expires=1467722352&Signature=HNZwao-OtNh1P1N6tIo7SNKX4JRGs85XyAJtTGMnmrklF5lvQUGa-Cb7JUtLb8OKniYG-jzHcraxszji26ZeAdDfqZ5YbSp6fLMS9wpBLnfsdRGjnp2xhjzPpCxxrgGoK-KzazPPYPkDSAxONZrcyBtwiHE9BLXFCmqXtvv5k5g_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=hw32v601.exe

http://hex-workshop.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/trmsvRChbxdrflJq3ZIylWuZIFnoHcEI7f5JH/dVbUsWkVeRCqlVrAALTHKvHjqRpNtUxm4/9eDprhk/16DxlTBSQT6tDPq7BF3/.../uHjRJbFiBQjWI=

Scan hw32v601.exe - Powered by Reason Core Security