movavigamecapturesetup.exe

Movavi Game Capture 4

Taukonsalt OOO

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from lb.cdn.m6web.fr and multiple other hosts.
Publisher:
MOVAVI  (signed by Taukonsalt OOO)

Product:
Movavi Game Capture 4

Version:
4.3.3

MD5:
55aae24d30074e99ba92b8d460881772

SHA-1:
9c9ddded2ef482f3ae13f092788d9289a22ab662

SHA-256:
cc1b408b330754b6d34adb2dd3945332f5a94a4cc3270b186066dd6518e585d6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 9:36:16 PM UTC  (today)

File size:
45.3 MB (47,455,656 bytes)

Product version:
4.3.3

Copyright:
© MOVAVI. All rights reserved.

Original file name:
GameCapture.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\movavigamecapturesetup.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
7/27/2015 3:00:00 AM

Valid to:
11/26/2015 1:59:59 AM

Subject:
CN=Taukonsalt OOO, O=Taukonsalt OOO, L=Novosibirsk, S=Novosibirskaya oblast, C=RU

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
5E0122231C6CDB4019DCA07DE5812315

File PE Metadata
Compilation timestamp:
4/10/2010 3:19:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:X6e+XOlx+1rDDVBCeqfSujEEkkmCxsaW7zt08ywLNYxC0BAs9n:Xvv3+l1BCzSXEkkAa4NYxHFn

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file movavigamecapturesetup.exe has been seen being distributed by the following 18 URLs.

http://lb.cdn.m6web.fr/d/c/a/8747755f32ceee73df21aea4b23e4cd3/58920a2a/soft/.../movavi-game-capture_4-3-3_fr_433073.exe

https://movavi-game-capture.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/trmsvRChbxdrflJq3ZIylWvlbaqpdHqn8d3TA/51bqWxUChQBieWwWEUCWarD1bRmAvuOBqinmBHsYa4D79irKo9bDJUxgpLU2zJgIFxwPEaSIBBgwIAsKBPcuSLa/.../Ogj7KyKnA7xbZcVD5BFCw=

http://movavi.com/download-gamecapture

https://files.movavi.com/.../MovaviGameCaptureSetup.exe

https://movavi-game-capture.softonic.com.br/.../6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAMOviqJZtpsP EeTRnawwZd8kfHX7cYOUNPgjAY4zoCCaOk1Wy8hm6UDJjRhhFIwnjJ0RlRiyvCOw8C5dDeYryL9AJBrfMhnxYiSqKpjEBvLb P7FHVgZvsAw1LIIqYx9U=

https://www.movavi.com/download-gamecapture

https://www.movavi.ru/download-gamecapture

http://movavi-game-capture.nl.softonic.com/.../6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAMOviqJZtpsP EeTRnawwZd8kfHX7cYOUNPgjAY4zoCCaOk1Wy8hm6UDJjRhhFIwnjJ0RlRiyvCOw8C5dDeYryL9AJBrfMhnxYiSqKpjEBvLb P7FHVgZvsAw1LIIqYx9U=

Scan movavigamecapturesetup.exe - Powered by Reason Core Security