setup.exe

GetData Pty Ltd

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
GetData Pty Ltd   (signed by GetData Pty Ltd)

Description:
Recover deleted photos from digital cameras and other media

Version:
3.7.2.442

MD5:
a2efff8e72162c71fc78a1b573af8661

SHA-1:
04902b676e0a42a2f79ffbe895be6120b095f9b9

SHA-256:
29e326c6433f0c98125c3bf69175f629e42e512c58ab7aa785bf35bf58c9c6e9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
6/1/2024 10:23:57 AM UTC  (today)

File size:
4.5 MB (4,668,856 bytes)

Copyright:
Copyright © 2006 GetData Pty Ltd

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/1/2006 4:00:00 PM

Valid to:
11/25/2006 3:59:59 PM

Subject:
CN=GetData Pty Ltd, OU=Data Recovery Software Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=GetData Pty Ltd, L=Loftus, S=NSW, C=AU

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A04E0B09C654E61F94F957BC9C8C4B9

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:UaBCU/1KG8S/yKt4Fe1UEIijkZfSYRovBz5eDbEZMK7KmJBzEie1Z4j9l:sU9KG/yir7jkxSYoy5K73Ep34j9l

Entry address:
0x98BC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 0A, 98, FF, FF, E8, 11, AA, FF, FF, E8, 3C, CC, FF, FF, E8, 83, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 66, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 1C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, FC, D0, FF, FF, 8B, 55, F0, B8, D4, BD, 40, 00, E8, BB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D4, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.9988

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file setup.exe has been seen being distributed by the following 6 URLs.

http://gsf-cf.softonic.com/049/02b/.../file?SD_used=0&channel=WEB&fdh=no&id_file=42881&instance=softonic_es&type=PROGRAM&Expires=1483198568&Signature=fcdzfdVy7dVqgojwweZiEJ7TlI~Hm2OhAJn0npeOVYdvDZTEKkXWnp1~s~oYw3CGM8edCae3~F0E~e20zPN~Dngo~EXZyqUwuuWQ0e5tz6W7Ju~1E9wCLAFp2MeLcnTZaoh26IHZUFoLS5HbhKVYGTyJmksWohIRsEZ~eN8M7i0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=RecoverMyPhotosSetup.exe

http://gsf-cf.softonic.com/049/02b/.../file?SD_used=0&channel=WEB&fdh=no&id_file=42881&instance=softonic_es&type=PROGRAM&Expires=1474386481&Signature=XHCBO0Weh0p4bsQIHDyR9QN94rvJBT357OIyVNU5ShvuhsWkoZQE08odFC~jyVL0the75AkNYfc2q4UPsx6bTAVJuMoaG9f~f0k5wJd7GyfGIcPA63C7jNzA2CkvOLrqWfcbJFJLFUhaI-Xm4RHriH7wkAF0Uu58g1zye39Ptl8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=RecoverMyPhotosSetup.exe

http://gsf-cf.softonic.com/049/02b/.../file?SD_used=0&channel=WEB&fdh=no&id_file=42881&instance=softonic_es&type=PROGRAM&Expires=1436096616&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=WNGrhZ0IkN-LiB0ckTeZMBdhJgH9sRfCuzI6YxkiFT-wBBSTg1kNIaRzt8TKQ44v1-vcIbcHvzacUCWbTbw7zx8h5Ud1QD-2N1q0HcyBV9Riv81jzeN6ef06Ko3-GtqTlGNa9lFL4FlXP-vVCVB3Y8CK9Xf0gdl9WZksJmoIXVc_&filename=RecoverMyPhotosSetup.exe

Scan setup.exe - Powered by Reason Core Security