icalendar.exe

Interactive Calendar

Vitaly Sokolik

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
CSoftLab   (signed by Vitaly Sokolik)

Product:
Interactive Calendar

Description:
Interactive Calendar Setup

MD5:
470805ff57c05aa07aedf8ab516209ce

SHA-1:
3bde507e94f970512df16c5595ffe84d1774588a

SHA-256:
b75e809bec5cb7b69ee5757a328e0a23c0195fe3182c59a81b02087b02821f10

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 11:48:43 PM UTC  (a few moments ago)

File size:
11.4 MB (11,971,496 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/27/2011 7:00:00 PM

Valid to:
10/27/2013 6:59:59 PM

Subject:
CN=Vitaly Sokolik, O=Vitaly Sokolik, STREET="Zheleznodorozhnaya str, 59", L=Stavropol, S=Stavropolsky kray, PostalCode=355000, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
42D36D05E3ABF217D124D82A581B99F2

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:wbpakeyKKDsheYdWed5mWWc8JkPEDisNp9JcFWxXZzWbAnit/opPJlrFigtg0:wbXeLDhe89d5md+Adbq4XdBx5JxFzH

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Entropy:
7.9998

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file icalendar.exe has been seen being distributed by the following 16 URLs.

http://gsf-cf.softonic.com/3bd/e50/.../file?SD_used=0&channel=WEB&fdh=no&id_file=321220&instance=softonic_fr&type=PROGRAM&Expires=1452908073&Signature=P6sDtPgmKAVYF8PiUIcBaahO~JlMIgm5HilYtnORFVRATtIyKIP--LjIn74HOAtfLFGqaDU3zFrmRRaY7C5kNxanIVDp1ssclEQsDZtPWLMuwU6DcAE5B88dNXPm-ob7-LIFRcr3m0yFVxg4y9qYx~RbLAGbHp-stcZXWFCam~E_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ICalendar.exe

http://gsf-cf.softonic.com/3bd/e50/.../file?SD_used=0&channel=WEB&fdh=no&id_file=321220&instance=softonic_es&type=PROGRAM&Expires=1441687571&Signature=P2VuT4bHrDILH3NLpbAKw3lZhQNQ7clrv8N8Vj7fTu~jlgeWXQJOczkzg6AAK~FJ9xC16rUO8vIdT6~0nOIPD4hdATvyhr6wswGGSTPE69eCJTlDMy5Q5nN7zAxng477RJecNSpTPrhn-3~oRASBSK7WDDjH48Yq8auuCUXfkFE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ICalendar.exe

http://gsf-cf.softonic.com/3bd/e50/.../file?SD_used=0&channel=WEB&fdh=no&id_file=321220&instance=softonic_es&type=PROGRAM&Expires=1476963241&Signature=aV6OtMVGZ1CHiIcjV5mTIPG94RECuUTObhZHtmp6W2r85V3TKSq4kE1GrLYlvO5f2uyYKgs7o2jNBKMRHZ340j8jGrc8PnaF~2Baa7fyNzo0doxgDbpAH6Tiz5Zcz-p2gtGKYRZlYqRJzZFKvd5CnlB3M~XQhrREBugcDIu54q0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ICalendar.exe

http://gsf-cf.softonic.com/3bd/e50/.../file?SD_used=0&channel=WEB&fdh=no&id_file=321220&instance=softonic_es&type=PROGRAM&Expires=1477306477&Signature=PbOvaXvlKUqLPF8bmAdbNAkjpJcFl4~pjowwuKrRBaFtqIDLhHCZXOgao-QKF4uSe4HyLW2WdYou-KWqb03arNKsTkhwUtuaVVtSOozptezYu7HlLqHSXF3lHC7ziOUhgwMQmXaIuFHfIvx2y3b2N7c46Q1sdgxGhCRPLsDadEo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ICalendar.exe

http://gsf-cf.softonic.com/3bd/e50/.../file?SD_used=0&channel=WEB&fdh=no&id_file=321220&instance=softonic_en&type=PROGRAM&Expires=1445023376&Signature=W8XOLxU5-ZqKhVXKHo3-zqvte6G7UjHxqNa2C1oqlvPK84Jtza3aStU8BdFphIVC1M74Us9vtUe4YKKYz8n6Wb6yooFypZU0N6Z2S0AsSqjnFggP9EcQKcIQnVHqafOQOgiP24iEUpoP756fWk40TUZz30KiP0mDrkZ~QM7zlco_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ICalendar.exe

http://gsf-cf.softonic.com/3bd/e50/.../file?SD_used=0&channel=WEB&fdh=no&id_file=321220&instance=softonic_en&type=PROGRAM&Expires=1447458502&Signature=BfpCvDYiO0wCW3Q81~snwF9UV6CMfJlRbwMtgjr8233Sj8QRa-VSlHxS-9kFPxMAP6lhpv3KoEOf7R-OUXIDI742GN9EbktCQ0VTnEM53F0CVqD-4RHAmK0FeyF8rg-qvxvyT33dijj4q87TbsACfiymsVO6ppLnO-iB6QK3Mtw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ICalendar.exe

http://gsf-cf.softonic.com/3bd/e50/.../file?SD_used=0&channel=WEB&fdh=no&id_file=321220&instance=softonic_es&type=PROGRAM&Expires=1447222501&Signature=W3F5BtFRtKw0ldFM96j0CeX7lT0rRO2f1YqsNOLknG0eScGxWrcWtbeX48~RkK9LA4AniF~tOtFLSAzcDUHD0mWNnGbDVYW~PZwRbY7QeR3hUIINrWNBAPKckFBftXJdeXiRbE7OuP8m5RUNCxP6~Ljq6yS92LeKVoIJ6MInAY0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ICalendar.exe

Scan icalendar.exe - Powered by Reason Core Security