install_easyshare.exe

Eastman Kodak Company

The program is a setup application that uses the WinZip SFX installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Eastman Kodak Company  (signed and verified)

MD5:
eff371b0b688e844f6fb404d5af2d12c

SHA-1:
d4725af6e42d49b2dfee83a24979ece235d66fd5

SHA-256:
6bf95bd2070d6f090b14062f4e69119343cb1d2aa5064b42fd99cce9d724b387

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 7:02:57 PM UTC  (today)

File size:
1.9 MB (2,006,416 bytes)

File type:
Executable application (Win32 EXE)

Installer:
WinZip SFX

Common path:
C:\users\{user}\downloads\install_easyshare.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/14/2008 2:00:00 AM

Valid to:
9/4/2010 1:59:59 AM

Subject:
CN=Eastman Kodak Company, OU=Digital and Applied Imaging, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Eastman Kodak Company, L=Rochester, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7F11526A8A2D9CC7393A7FF7FE0AFA39

File PE Metadata
Compilation timestamp:
1/9/2001 3:09:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.10

CTPH (ssdeep):
49152:uOBMRny2TR9GkrUHodi392WlxD3jekp3C+MCOq:T+RnLPgH32WlFTeS3O

Entry address:
0x3F8F

Entry point:
53, FF, 15, 4C, 70, 40, 00, B3, 22, 38, 18, 74, 03, 80, C3, FE, 8A, 48, 01, 40, 33, D2, 3A, CA, 74, 0A, 3A, CB, 74, 06, 8A, 48, 01, 40, EB, F2, 38, 10, 74, 01, 40, 52, 50, 52, 52, FF, 15, 50, 70, 40, 00, 50, E8, 9E, F3, FF, FF, 50, FF, 15, 54, 70, 40, 00, 5B, C3, 8B, 44, 24, 04, 8B, 40, 3C, 05, F8, 00, 00, 00, C3, 55, 8B, EC, 51, A1, 88, 94, 40, 00, 83, 0D, 00, 93, 40, 00, FF, 56, 33, F6, 39, 35, 40, 8E, 40, 00, 89, 35, 34, 94, 40, 00, 89, 35, 84, 94, 40, 00, A3, 24, 97, 40, 00, 75, 05, E8, 9D, D2, FF, FF...
 
[+]

Packer / compiler:
WinZip, 0x32-bit SFX v8.x module

Code size:
21.5 KB (22,016 bytes)

The file install_easyshare.exe has been seen being distributed by the following 29 URLs.

http://gsf-cf.softonic.com/d47/25a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=40301&instance=softonic_pl&type=PROGRAM&Expires=1476592345&Signature=G~zOBcgSaN3fPeuhGdzdTiz8fewzwMSN4w9MjNxIJKaI2-xCL8MZQSqvBSD4TDVPm0uPh9p14ND4XmPALZOpv04NE~-0LPqwFmw4QHAVBlZWUf-QSAU5E0ux6g2zja1QayHyc60UEQWHucNC4VSmiGXTqPu8yw1S1xTn2o8Bcws_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=install_easyshare.exe

http://portalprogramas-download.com/d/.../kodak-easyshare

https://dw.uptodown.com/dwn/6ZF9k2QJgaM5QnnV1nyWuMl48Q4B82cxBZnWDjmubcTUkhRBDTDlzpaVpUJfpIukXAZoRFfY7akOFcGevLXGX2dwmgCDvNFOvVga9h0iVaYH0w9WyrWkQVZLvTzNIj9D/EUBI8seMgIUWJBIZSnQ2a9ScR6bZ0bzjaMpNWw9kJCMngeSVo_IYxypApGfwljKcq25v4Jh4-Asnu7gqW1J_cJdsJsvzU_8RRFt634mK8gjgeyfYeedsPOU8fWYEVs5J/hIAhNZjqXuT3XqF2covNdTm4vYmuvzbyOSTGVGZCSg3mn-NsA4Mf5Thpg7wcA_gtd5Pmjr1PXCkBD8WziR2Tu_PmzVtE_JmA2TrQ8dXDSnoiLiRGeklE5UHftXzbVJrI/.../

http://download.freewarefiles.net/.../install_easyshare.exe

http://gsf-cf.softonic.com/d47/25a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=40301&instance=softonic_pl&type=PROGRAM&Expires=1464906201&Signature=Pt79qZHeC08YFilC5QuFs17wQ0gAwCxMfmWLyN2opS1cozUAx8RRiRMSInthhytIuCY2~K6XyNrPsKrmoPhvdhLLLF1VhX-XEIrhIr8PJXseiNvG~NdYzt7~J~367NssygO-mjzwyW5nOEzCFNsYcOyreJu5fWt4I7MCO6zlFSE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=install_easyshare.exe

http://dw.uptodown.com/dwn/E-2upGRRS4MT95kfcRwO032c43aioxwXEv8isZ4A5zIGxhci98-Z7bpIR5zViJsBlpLRJc-jvmMY-Q0AcuMtRcjA6vscVIZbY6xOQNt8frDCgAjIk_VDcmJYtAim6xAL/1nMmzHfuGEIF1Ku3u-2rBedmrAQmEpnXe0fA1VeUb4DavqfpZ4I7BUqcVA1g2NWiydrw7PZPOWkPAu5OlkJ3jCwVO41pgGYoUJga6itZz_nykWlxmWf7ZIN5H3LHNOZL/HP1WzPjVaxlJKsFuNJQtVUVwFbY1Yxu6_SdlC0gRqKZqGNlC--DpHholDsBbBCwFq44D6bIsGhgZI1yBWGHz2i92YXEQG6cjM3QDj6wWtsZoR4BFNGWYTJ8ypB5Pd6hF/.../

http://ec.ccm2.net/en.kioskea.net/download/.../install_easyshare_8.2.0.exe

http://dw.uptodown.com/dwn/xIUd2j_chFR3zZV8jz1uGY-kNU7XqTrqT2Vc6662UaUjyyU6ZGGEBY4p_lJ_5Utot4ZDaVwSti-fiP2fNIeN6W8NDzd_Ckw4g6T_hx3nAdVVXX5VmiMWCeXgrOwtO7BA/.../

http://en.kioskea.net/download/.../download-11180-kodak-easyshare-softwarer

http://dc605.4shared.com/download/.../install_easyshare_820.exe

http://dw.uptodown.com/dwn/SnTAVZmvsfZVQ3yW9yZqs293VVUNs7Sg6vwvVNWNHZ2-QrFUSKTUOYgLaY_lctHTwHqHuqyUwcxdsaGuPTVo1aAcYkZHYPR-gKxQW2paD5H0BJDTMJ5FPdK8vK9q3x4z/77XlGAfTTgxg-A5P6kJT-3OAkRp84D1bcd7_-8Z3io0D3oUWkRW8Ega8J97Eq-aZWYaDZbfG2xPPnTeIQvla4623yRgTGXtwByEhgYXW8uLgSb5y2HOX7SpIolSTDnHr/.../

http://soft.mydiv.net/win/dlfiled317e_199353/.../install_easyshare.exe

Scan install_easyshare.exe - Powered by Reason Core Security