setupswishmax4_20110620.exe

SWiSH Max4

SWiSHzone.com PTY LTD

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is installed with the program SWiSH Max4. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
SWiSHzone.com  (signed by SWiSHzone.com PTY LTD)

Product:
SWiSH Max4

Description:
Application

Version:
10.10.29.100

MD5:
d162aa3d87cc19f12b381300c71ec890

SHA-1:
3acda5360854c3aef2bfb9629513ae797370206e

SHA-256:
0df84a7e486825d85684575f251aa45ac071bab31da7464aaf3d396c5bd34425

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/23/2018 4:06:48 PM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14316

File size:
54 MB (56,654,648 bytes)

Copyright:
SWiSHzone.com Pty. Ltd. © 2009

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
12/4/2009 7:00:00 AM

Valid to:
12/5/2011 6:59:59 AM

Subject:
CN=SWiSHzone.com PTY LTD, O=SWiSHzone.com PTY LTD, L=Surry Hills, S=New South Wales, C=AU

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
1E55EBFCD5AB6260A3FD6689267AE5E6

File PE Metadata
Compilation timestamp:
4/10/2010 7:19:38 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1572864:AOAIBk+zDkcQ9KlAZy/aRFqsQ7XsY6j7zvfSYKV5P64JFzZi63c:ANIBk+z5Q9EAFqss8Y6XzvaYKV5hVj3c

Entry address:
0x3415

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 70, 85, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, B3, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, B2, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 6C, 85, 40, 00, FF, 15, 80, 81, 40, 00, 68, 54, 85, 40, 00, 68, A0, 32, 47, 00, E8, 35, 26, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, C0, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.9988

Packer / compiler:
Nullsoft install system v2.x

Code size:
26 KB (26,624 bytes)

The file setupswishmax4_20110620.exe has been discovered within the following program.

SWiSH Max4  by SWiSHzone.com
www.SWiSHzone.com
About 6% of users remove it
 
Powered by Should I Remove It?

The file setupswishmax4_20110620.exe has been seen being distributed by the following 48 URLs.

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_en&type=PROGRAM&Expires=1486422263&Signature=VHvUBKn77muGt0XQwc8YhCBbQIH488IHMoXptgcsxlA7llA~h9Op8EsPaEjo6faQ5NUwby6Ek150gcIktyFbIJFQVw~g-QEsnUv-EjzpGQIMc5bS4m9b9BiWI3SNQ889Ho6K8EYyJWtYR6FMeVkHXLgDT7jXb0rYgdXazL8IUm8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_it&type=PROGRAM&Expires=1483600404&Signature=WM8C-2X1mz6rHUjryFChZIyTobwUvwdSmUxX~KjVCFjJhtAVRM519TFkYjiAOPWdOK5Ar975izaZ5o94LXM~rP3TtEjyQ527KzcQtZiRNxrpmEuSqLaCtrVw2iMFljeWg7I3myuhWu~m3Xef6namuaCTQgYBRXhxBcnQRFo0c4Y_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_en&type=PROGRAM&Expires=1484613028&Signature=aX-zLgFreyhJSurnfN46zws3A2F4z1fWe6mfBUB1jK0Sx2pWd5fYj8PmkRC6JOCyHBD2Unrv~oED8go03ldqRyxYQrFm1z-m8oyn0o4A1H0m4gjGwngq6zwg7GVGwLq-QVagOoKE3JnDEdmxJRO87tSe6ZLDw4MzkhcyMxXvUmY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

https://doc-0o-9k-docs.googleusercontent.com/docs/securesc/df6q24tvc03d9vofjag1bcc3a50t2jn6/ms3434k73ieqnj37do0ovuuupcuir7tv/1481767200000/15504102720654639791/.../0B3VDFor339CBdGNQUmxqUW5ZRk0?e=download

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_es&type=PROGRAM&Expires=1447902397&Signature=JJlEZrL2Y7KBBfVSNm~821~xfuWq746g10BFJj84tl75e6L6jRx7MCIw5sSUoCOfn774C8ODWjtdhjU2Qk6BaHVtjvQoTeamnGef4PE5FZ3wjy2re0HflqbG2WMlH4103Xvl3rSMZaXLochnadATidvuAqP1wSFm2FZ3309QowM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

https://doc-0c-4g-docs.googleusercontent.com/docs/securesc/153k3bui1ojdt5pnqgncivm2oulrolup/5o7ni4vge1nlor2h8b3mohcjs9hope2s/1471960800000/15504102720654639791/.../0B3VDFor339CBdGNQUmxqUW5ZRk0?e=download

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_en&type=PROGRAM&Expires=1480465840&Signature=LBPDCxTsQw2LLgMp~goxP2fsqS7XxwLap2kc5NKEYnJcqTpBuHHHm5ExlTNJOvoWFQbVmaytqXlUjvHdeyW1qjXOyVAs0F2bCBS~ja6E3SiVXU2BorhxETpwfiANMSqT4FjXvwutgBM96scwhn3tmSOur8hYa7PHNZfTSa9gfZg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_en&type=PROGRAM&Expires=1475801518&Signature=ZY0FPgDvwuhA~Yb~iBF-dF3PU19XwGjQ-brlni-G~0YexwTy0Us6ZEnwXSGUzbkeO8n4~dC3YOLjEFeB9WOxd3H3zKH~XwzJuG-h-ss6-H5T0IFM8CkqDc87Hax5q9DJX4htS7cdYZwLS0yvz5dFBWPbnPznDO6QYO~U8wWDS5g_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

http://lb.cdn.m6web.fr/d/c/a/ee7ec2882cc67854cc9cf80ab694a7ec/5644b485/soft/.../swish-max_4-0_en_67224.exe

http://ec.ccm2.net/ccm.net/download/.../SetupSwishmax4.exe

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_es&type=PROGRAM&Expires=1441003259&Signature=iHYixDOPKjfiMtpr9SDY6hpehetEmjsRpAgvqgPIDSOCLLkfnT0G55~onH8-XtsgNZAqO5GMWAH9Tikw1s-mZXitOSO1iBYaCdR-BkfqRLkakBBoVClV9trULW~OFUu~rhBziophb2OCr1M-tq8VVAc6jMXpcO8tLLSodIjUy98_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_es&type=PROGRAM&Expires=1478322910&Signature=F1VBjmqsBF44uULx-f47rW~OKPs8ah3p3Y5S4~aRWX75yZM3ABtMeL-u1cdgzjU~P4l7KwAvwZTdMUsZTr9yRwRRJWWmDeC1hMMVs~bEm43efQteEYzsyKTBCREgtgdx5SEQ~pRkzdudpXeSSxAsrmNGH2MhfDQ0CqjdUXgn1gU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_en&type=PROGRAM&Expires=1476895389&Signature=cJFv6Q-tADx9lltaTd71zeQqsTwYOZcYn7nz0a8gJXqoAgyu9iBTCGWrFlhLFPKNc0uQW-9H~AJwy3fswbIOztMjLtSRJ4gMEfw0zpjx-IevMcSa7yg18ae7Tv-g54~a9VQjZmWlVPUbnHwPiIyy7YuNUkl3LlL~tNgDoKso-vI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_en&type=PROGRAM&Expires=1425332637&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=R3SJtM3NanQepJR9JoR2b0Vgl3STE0WYTEoCc5jEk5K~DFlgoaoY3nrI4TAYyb3tLp1~HWQSSgTjrJ7-cOcsPNjJyqbitzDWn0ldlKoHEEZNJqs6TTCoTyDFT81Mw6FkirjJA6ik8MtDUSSvQn6l4pqkaDgQo7ZuuMjTFR8lybI_&filename=SetupSwishmax4.exe

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_es&type=PROGRAM&Expires=1478584280&Signature=VngoUvLSnFst23XgP64v10sWCqYyjgjdTHr4bbnq8EM9yQMo5VmRHckv0Gyky4kB5qZE3e54UeimpE7fnprghdExs3XC09FsnMueXzzH0oZByj2wmZxpmjFer-83XXUtHcLTlg9sWDEqTmUNTNyTaQ9TiSW8CqDVh6BjScA6Axg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

http://www.purefoldercity.com/c?x=25PlKPdhPDS5iqI551Y/ggIlR1LxDh5XTAPQxpqF5Hc=&c=C8vKc9ijgAGfQr1DNw3la4VhV3nMZOL 1fF5KG8yVJxohAh8FVRWCqjF96DLcnCtg5gk8ViWhocESBh5 8lZeRKr0HvbTJPcGEtC TZLSh49pB8arekx6FWQchLBtjPv&downloadAs=swishmax.exe&fallback_url=http://www.swishzone.com/.../SetupSwishmax4.exe

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_en&type=PROGRAM&Expires=1474661944&Signature=JO~h67ks7ZoObVnM8YBFS4jce5Xtlt6aBEeYEbZPb2x81t9holksmxJuhmkkzigWAC7Bj4xVpah8kZ8e0CY0RVhxtj2wHHe9JKmi8Sp-ao3q3HVRaZGOb7acOVGtf~OTRvF2tVnG3pLivh0Ryyy4x0Z8L9TZGwXAZx18JQ~7e8Y_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_en&type=PROGRAM&Expires=1469069663&Signature=AZkXXsihjl5aEMbvWrIZzzWkeWMj0BQDwfs0ud-M72eNjzD0~N6N7~I8ojrhRRaV0BMdOi3iRLxxmc9K77BQGENnMx4mRTMuePSmxmkpAmHBTg9883YfIYi03MiolmVAXlsR0jks7JyIKMfJeziR7BrJAPY0PpSDIKgVjXcaz2M_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SetupSwishmax4.exe

http://gsf-cf.softonic.com/3ac/da5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=14195&instance=softonic_en&type=PROGRAM&Expires=1429670861&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=Py5m1co1LkWKLAKKJ7miTx06vver-ue4q-2Vv~LX8v80mOyJtxywebj0v0GLHUxNIsomq-zx0b8bSkX~dqFCkhfyhub2cb6Ox~vboSThrvN~j8MTDBMZfGw6bHRtm-bh9RfwwxfVzbWnXTAtc~ljO2uJrIkz1D1cYRzcowG9jRo_&filename=SetupSwishmax4.exe

Latest 30 of 48 download URLs

Scan setupswishmax4_20110620.exe - Powered by Reason Core Security