player_setup_full1374.exe

WAC Downloader

Wondershare Software Co., Ltd.

This is a setup program which is used to install the application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Wondershare  (signed by Wondershare Software Co., Ltd. )

Product:
WAC Downloader

Description:
Wondershare WAC Downloader

Version:
1.0.1.0

MD5:
ab37a90c0d5ad3bed5c2c6fdf6f540ac

SHA-1:
c6988c356ca98619e6db877160e823ca6d2d3976

SHA-256:
a708582f2430ce1d63c08bb1dd4cd94aace3be992da316c7e5b118063f3b006b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 5:46:24 PM UTC  (today)

File size:
904.8 KB (926,496 bytes)

Product version:
1.0.1.0

Copyright:
Copyright 2011 Wondershare Corporation

Original file name:
WAC Downloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\player_setup_full1374.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/22/2011 2:00:00 AM

Valid to:
9/21/2013 1:59:59 AM

Subject:
CN="Wondershare Software Co., Ltd. ", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Wondershare Software Co., Ltd. ", L=shenzhen, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2649593DC86804A0829FE1CFC970097B

File PE Metadata
Compilation timestamp:
7/30/2013 11:35:29 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:1FxqifK2DKbDgrWOTBuBgDU+WfhUJu4sH5Ojbd6DuqagTb3f:1F5PeDjOHDU+WfhUJu4FM9aQLf

Entry address:
0x2D3C2

Entry point:
E8, 42, D6, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 4C, A1, E0, 96, 45, 00, 33, C5, 89, 45, FC, 53, 33, DB, 57, 8B, F9, 89, 5D, C0, 89, 5D, BC, 3B, FB, 75, 1A, E8, C6, D9, FF, FF, C7, 00, 16, 00, 00, 00, E8, 2E, 80, 00, 00, 83, CA, FF, 8B, C2, E9, 65, 02, 00, 00, 8B, 47, 14, 99, 8B, C8, 8B, C2, 89, 4D, D0, 83, C1, BB, 89, 45, D4, 83, D0, FF, 56, 3B, C3, 0F, 87, 37, 02, 00, 00, 72, 0C, 81, F9, 08, 04, 00, 00, 0F, 87, 29, 02, 00, 00, 8B, 47, 10, 3B, C3, 7C, 05, 83, F8, 0B, 7E, 46, 99, 6A, 0C...
 
[+]

Code size:
288 KB (294,912 bytes)

The file player_setup_full1374.exe has been seen being distributed by the following 23 URLs.

http://gsf-cf.softonic.com/c69/88c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69671521&instance=softonic_es&type=PROGRAM&Expires=1446389439&Signature=SND1trHBFOx-l9dLQerkXhdMntnnh~1EgIb6KBJIhZO5iHkz4bOg4mnVzKxzH06iezMYBIBNWdJvkqdJK2hxB9y0jykhOMtYFBRfkAbvJWg6AGeoQRAihhvjI3dQXwtMz5NI~ocZgBXVV3nn~ahplr4~UrXKys6aMsUmbMevcfM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=player_setup_full1374.exe

http://gsf-cf.softonic.com/c69/88c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69671521&instance=softonic_es&type=PROGRAM&Expires=1474137914&Signature=dSarGdMjAy1SrH7ZNVrlK5mAMcKSv09fW5rmMToNgTUtlB9dviepzm38enVmxt9mH--iTUzbCjelm-pQXTPhJlo39pCLjwS00r7oKcaYmk1dEaMaFOFwzeXduowV-DJuWSl5oKavbcndrKggNVH8yXIyy2x4mForR~xeXSnj1jA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=player_setup_full1374.exe

http://gsf-cf.softonic.com/c69/88c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69671521&instance=softonic_es&type=PROGRAM&Expires=1481861277&Signature=M9yePgkiNzNN6w0yPUYNwXehrl-FDt4~x3~2LFXVC-Ve5cALJht-i-8K69bbfATDYlPzXy0hpBgnrqJau7r25b1oWEqa5GGPn6S9UP9kCP2GTTSWFMqXPP0uJs0nKGuwJnbOm-Dmk05e-q53GSWGG74ic~uroZQLWELjmXDmkbI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=player_setup_full1374.exe

http://gsf-cf.softonic.com/c69/88c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69671521&instance=softonic_es&type=PROGRAM&Expires=1438962119&Signature=CCKKwYQCUGJm5duwjZiIH784pf0lWkZSv9EgB2BNeExJiijohDR2X84a5E~7HvZD4S3e49UAxvD2XJcVwJPlPpUSr9Xm3ZMcEjSnK3WaQOQ~Z0~gNxhJJUTJUtRckJDE0W33DOGSczJfsNDG4t9VwCcyskctqu1bxh94snFfPO4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=player_setup_full1374.exe

http://gsf-cf.softonic.com/c69/88c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69671521&instance=softonic_es&type=PROGRAM&Expires=1477919822&Signature=M1oOpbgrtpzsgttVde~Ezqr-SkSjB-ADYvHqk03nlIBhYP60PJSV8EcYL2KZdUtzs19Q4PHKjxklhzdtEImdOwvkjPFb2OtxcNcqW6SyLmEL9BW4t3SC1fZT1iixNVbBc0q3kjCgZqr5rnRIgmJDUtX34Lj3U8Eul1I5GKhS3Ks_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=player_setup_full1374.exe

http://gsf-cf.softonic.com/c69/88c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69671521&instance=softonic_es&type=PROGRAM&Expires=1480371155&Signature=fG3jdSG9PQ1rT0er-MmPUzwQbcYvAl7JpsSVuK4NCkCvpOPyck0mIg6a4FBOgGOZcMYYX-TuWB67KWOyiL-cpSO91fppN1dyqWUjYDcV1ODwzdYMw9JLaViJOB~J78q6kqAVzfNXzthawFtAQNliXz64m8SqUbax7s8bfWxUnFc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=player_setup_full1374.exe

http://files.downloadnow.com/s/software/14/42/35/.../player_setup_full1374.exe

http://gsf-cf.softonic.com/c69/88c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69671521&instance=softonic_es&type=PROGRAM&Expires=1466849866&Signature=HhnGZgNjRbWJfgRy2sHw4pjPX0QzuxYPS3NTH-T3anyTfkPQLCIHVYXhcq1pIncYuB3a02K0wDW3zV0IAVTtwlOIR6UMnUfG6qS5-GFEZyGfgLCijcMGHeFHL8Af4Kkwc3Z3Pq6AOduZRoRv87eZSS-rotN-tHze0lc9dYHPW48_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=player_setup_full1374.exe

http://gsf-cf.softonic.com/c69/88c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69671521&instance=softonic_es&type=PROGRAM&Expires=1477220415&Signature=MiesImBf9IAFl7PVA3EURxDwquAyXXV4SdB2okH6oXzBHCXZlLiBtkpTnCWxSWO2EnIk2WkIORvDcayKVNQwpt2AY47mSa-v60pSpvabIcoPT1PkddBB6xRMbes3qY6Pt~BkKnkNG74dV9QVA-u4JTbXmeJ74L6oGX8p~8TfnxU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=player_setup_full1374.exe

http://gsf-cf.softonic.com/c69/88c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69671521&instance=softonic_es&type=PROGRAM&Expires=1466603920&Signature=Wp9jLwGNxK9T7tXnyvEDlTuRQB52akjqtWntg-w0qBle7PPx0-3V4WZrDwGJSnJ19Vm4Mpn9Ihvdltbajl8rXxauES259BB5s8TLZKjoGZelnSRi~KhJ9iV5MUlkpTkVSikfJfNSNFfOba2f8uLqr6k1DFmdEd~x8hAMlWMG8bk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=player_setup_full1374.exe

http://gsf-cf.softonic.com/c69/88c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69671521&instance=softonic_es&type=PROGRAM&Expires=1474366976&Signature=HgWGcq4I90vtbAz4ln0-KQa4S2-7GY8-X~ffYNqU6lo8VHluYHDuEuWFSXVrseKSsU97umfmAdjcunlGrXYTCs16Oq~NPq7q-f3HL3s9LeDcHimi3mmAsmv9GZlDLEQhutfhiAnVpk84rxiU2CxnghG1jlsb5bkT5f82mzG~cOc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=player_setup_full1374.exe

http://gsf-cf.softonic.com/c69/88c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69671521&instance=softonic_es&type=PROGRAM&Expires=1445608733&Signature=aih20tJa7FgWuRftbX7SmewFU1xZ4S011MXf3Ih9-SH83Tn5AX6I2Z1ZIuUPBJhTAiULmMhTyE4jfTn3~Jo8dqdzT4dh6dlkKk4tOtI1elMr4pvs7EA42Oml7vGE9jVqNwp9BeeaNDQjTxpnQmoh~~BzYc5Ja7r1dLn6oTRJaRA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=player_setup_full1374.exe

Scan player_setup_full1374.exe - Powered by Reason Core Security