macrorecordersetup.exe

Macro Recorder

Alexander Yumashev

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Jitbit Software   (signed by Alexander Yumashev)

Product:
Macro Recorder

Description:
Macro Recorder Setup

MD5:
2b680341f375f3de123b41091d02cbd1

SHA-1:
a5ddaadefba80c14cdd070b8620b74590bf24b22

SHA-256:
5eba26a34daa0ee76fa4c38ec6d8f4cf5681c50fd576f47cf2d2458eba65a8ca

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/16/2024 11:01:18 AM UTC  (today)

Scan engine
Detection
Engine version

Vba32 AntiVirus
TrojanClicker.MSIL.Agent
3.12.26.3

File size:
700.7 KB (717,536 bytes)

Product version:
5.6.6

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/25/2012 7:00:00 PM

Valid to:
1/25/2015 6:59:59 PM

Subject:
CN=Alexander Yumashev, O=Alexander Yumashev, STREET="Kosygina street, 13-214", L=Moscow, PostalCode=119334, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D48209C4563DF0EAC268FD22EAFA0336

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:/QFaDOF9aloxYQ2Te0u4NfQ+YRDus0XyQtfbwPGDg4VFsEP7M0GD9T4ZewWBvEHZ:/QFSObtaJa0VpYAXyQt84VFz7KD98Gvu

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file macrorecordersetup.exe has been seen being distributed by the following 26 URLs.

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_br&type=PROGRAM&Expires=1484552462&Signature=MOKUctVym-~2UBI3HVIB4iPahB9HN7uROZL7rLFgcIArJQXNdAOlBZJUpN-T2m7ZKyAJ~fvz53Y6tuQOEX7dcMHhlhlXfndID-vagSC4e0gIfJSm73UanY8IHAdFT4rR645MuLczgDE4sFPVpR70ng6QeoQSk9GLG1rCHmdgm04_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=MacroRecorderSetup.exe

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_es&type=PROGRAM&Expires=1484921036&Signature=fhFLHVeFV1F2Iz7121kQDgoBPmfUACn5bR4jy581ShiyeTgVyhc1JU7nJGIJ8Ye-3pp6y1coS1rr9A-q~COkLLPqeiICQNxH2V1JKB4rFzH-SVsc~kOO7iqYwcSUSwB8S15kM-k0~XP-VL209v9QG9Y0FVEg~5VCQgDCZnOgaqY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=MacroRecorderSetup.exe

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_pl&type=PROGRAM&Expires=1480900058&Signature=Drj9NKxj~hdHsvgByGYlpxsnk2oeU0nrU2gNT3O8FRWD0WPU2m5j2~r5bWgu8gzl8Rkt6JO91HdSVLizRHPKMeK6DatJgIs8hVrNNHbF~K7ll~vlPZMuNu8tVTEXGU1CpxRPdbFMzn-5jewTwNFJqm6oar5eSYiIxlCqyJi9Cns_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=MacroRecorderSetup.exe

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_en&type=PROGRAM&Expires=1472028761&Signature=M4dQxLTE2CzAJLQdYEXy9hnGiHLOkOFj1zqk~1hiU3z0Mgq3YnjGpNWiJcSYo0Kj1wRIhtiCKFvtecWyiRVIGt4H-ZzmrLjKqhyZ1m5GjxXyDWDEo5t2FJw89cgNIV5e5NO2hcbYPZBN6dM4x-Sci0yTLPTT2N~Mrakk9X0iN5k_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=MacroRecorderSetup.exe

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_br&type=PROGRAM&Expires=1483409394&Signature=dI6yXnHzvB1G18msDj4ARuqYqZHWHXBCx9o7bz3KtPC4VD2qd4xYNebTvcI1kPqhJ4Wv4A6RbhJfXINRBlyk7VMv-aWQ94VCmVWk6txSrXCBcPQ1kOESUcbNhCR2AAVslYyi0niOwAointrpIbRSEVxqjwzTndmZ4rZa7lmWOwk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=MacroRecorderSetup.exe

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_en&type=PROGRAM&Expires=1462376856&Signature=HgB6063x9NrlPhnR7WaJf9TjA-H6M~LmGjsBjD0uD6crJR03eStygdz7zvbDgDerJ-VqaQVUrI9ghmUMN8jNlWY3ciOFOOeapPlrjs2WmqgElnN5jmnlx6z5YstYBON1GXtSIfpk-k6J8GgL1upbd3NRZjmcufWKu7U3SGO3egs_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=MacroRecorderSetup.exe

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_br&type=PROGRAM&Expires=1478069123&Signature=QuBEWD-XdfUHWoL-FmsA9pdaAzvELlJCk9J4EY48pn2ZNBIRcmhTn1ARo-lPbxBj7VlLYzES3ybYwPi3fkEa419e2YzAY5n8QWwS91ezvspxIWPgBeJ9Pk4r4yAA6wq5GwvwLfoQ5RW0BGcg2LenuA9IhkFYrewBgAO25XRXuSE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=MacroRecorderSetup.exe

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_en&type=PROGRAM&Expires=1476092160&Signature=RBoBv9rVCPOuc4IwHc8FGNtfT~gVUG15iRo3V1IxrgAi9frExwplBOwiMojSbZvu~XM87anRGpUIXUdnCRmsPuh3R1NsiKJnB0MLsDXdj6x~rjcfu7E44XPtbUIdXwdzZtf~fq2cvVFDF-FEU1q80-xr20hO8RuqNtYhr-aeUtc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=MacroRecorderSetup.exe

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_es&type=PROGRAM&Expires=1469036799&Signature=Gd4ebLFBEf2o5fkZyRyyCsAPDeX~4dCf5JspFmy6DlztK-PvReDt-oylQAer3bi6mOP8Ro~QYcwAlhAazqDOs2sM3eO~wMzTCfRRET07yGeBOB3c0AxbFt0SoZvlYsYPy9tb042PA8wkpy1apYKsCn9y6hQ-7YFa3Hfa~j-8CXc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=MacroRecorderSetup.exe

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_en&type=PROGRAM&Expires=1434588740&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=Xcll171CphS7QNQ2vZJB8tb0jD24R13TW5xn85pp8v8Kg8XWQdzsF-m5tMsLi45yypqd7sHxvvKwOnstSNuLeo3b1A~UR1WGFrZ8dB6Z5lSU45jvzMMaRjrlAygZDlc3l8DG8lzkcbhUDIc69SQ0p9B8TBulo6PbZDVO-Bq-0h4_&filename=MacroRecorderSetup.exe

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_en&type=PROGRAM&Expires=1473774734&Signature=czRZnmO6JguHe132R8EtrGGzCeqAQQYOXGbml5KghTPDlXdnPExiiJA4Jx4YEQvVvvRg0q5qJ5~vPiNiBmDkZW8QRSNH5BwtOwNoDb8vstTyci2olye47KbJf3rgAS~f3tsUQWMN74CLbZu-VFpStKK~HjAri1Vvm9xRza8QuvY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=MacroRecorderSetup.exe

http://gsf-cf.softonic.com/a5d/daa/.../file?SD_used=0&channel=WEB&fdh=no&id_file=65012&instance=softonic_en&type=PROGRAM&Expires=1468046378&Signature=c~RlJdReQ~jDbFkWYQuTGiUb60AQERIgGb4coSVQ8nOyL5eYagoOoi9zRxWMJUA9Ih4gPuMJDj762rSQ8eEhlpa8itYGLPYahcwO0kUNfNHfSgPl0jZ4YxNOZZ4g6jb6LVfzSGv5Q0URWYk5Pku1KSrpXdWEavPh-plAc-dk2C8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=MacroRecorderSetup.exe

Scan macrorecordersetup.exe - Powered by Reason Core Security