smileboxinstaller.exe

Smilebox, Inc.

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Smilebox, Inc.  (signed and verified)

MD5:
0eeb9f341d325fffb3fc1fba24545fca

SHA-1:
f1c8e254c04afa5925049474eee6cd3c56648ac8

SHA-256:
3886059886c17c1dee5e3882bd6cae075d7cdb728f838124499f494a08f815fe

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 11:26:41 PM UTC  (a few moments ago)

File size:
361.5 KB (370,128 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\smileboxinstaller.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/11/2010 1:00:00 AM

Valid to:
3/12/2011 12:59:59 AM

Subject:
CN="Smilebox, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Smilebox, Inc.", L=Redmond, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7BBD9B26630444A23DB456F1F78D731A

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:Qe34/atu/T0rJvpIdZSF2L/F3FK8RewaF9cOX43CBCEtkBA3lzCadPsYeMfL6gGl:+a9JvpgSFm/FPAPmOXkCBl1zrGYeMf5i

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8675

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file smileboxinstaller.exe has been seen being distributed by the following 21 URLs.

http://gsf-cf.softonic.com/f1c/8e2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=96059&instance=softonic_br&type=PROGRAM&Expires=1472049472&Signature=OXwx51a4bnVqPX8PWs3zVQWfxsRLtYF8KFllCD-I9E6WitbzWL4VaVERcG15nnJhc1Ik~t4UeZy~iYo0rldZUtnHOLdhmSDRosxLPy3GSMsEjenCVuWwF2ruqCmtVYU5--tc4phFzkh0UGedJ-8LZlSVBSuUMkjXOFSQfhBiyvY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SmileboxInstaller.exe

http://gsf-cf.softonic.com/f1c/8e2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=96059&instance=softonic_br&type=PROGRAM&Expires=1481009383&Signature=KJssMFnselXgNYFAt0rKnaX~gq5woQlXxDV9fW6b2A6QtmzETjfpi95Ee-n7t~eyfxXrIYIZzbFL5D9C6oSE70bAVLEKVIgRA8D~w~421-k814WJ25uSMuhEIXsbuXHLmN4sX5SY9yC94~BvnbhEHOMNzRtXA1mxvJh6X~AwVTA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SmileboxInstaller.exe

http://gsf-cf.softonic.com/f1c/8e2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=96059&instance=softonic_br&type=PROGRAM&Expires=1482451198&Signature=M9plvHsdpkPix6ihITE98mtNojAbMdVpCeSwogh0JYli5EOomf8EeJ4m~ZZtKfoUAccC04QN3eX868ApD4mXl1fTMSJ4oJOvif05r3ddSIXw2ltrharpVwYRqo9h5NAfUeuVSynC9OZ~cMq89VtJyKgTqxbJwevhJha2KGTVCDU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SmileboxInstaller.exe

https://dw1.uptodown.com/dwn/FLhniPL-yFo6scg1MuFKNY559Ys1AhMGTQT_ueCsZiLM1k3BwAU0z9krCtdrH3RqLVGyWoYdtWJNgqeImjppnHwHHWvh0UJkl7yCDSEoG41TOeUSr4jL9ee36hRRHySk/APuZ06gOsXFIKwnyI9KcoEWDZ3qeG3D2xdf-SOhyHKfe_IY55BBNLPpmoT4Hl9hqYPmCvOxQ48lDi_ie6-Yl3kbFSuJInLJsijFThoaxcmYlzWBdpnsoP9_zlscwF41r/CU5ZXNNm4FyFD1FGBBZu8ked_czVUEio1hu9veMJZSZ9CvXZA18UNAso3u7fLmNe3jIdniLtmFS_HdgSIGYGehGn_LeWvhuUYSwwJ8QT18__QiWybkKN0jiQ6yghCge0/.../smilebox-.exe

http://gsf-cf.softonic.com/f1c/8e2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=96059&instance=softonic_br&type=PROGRAM&Expires=1468208556&Signature=XG5Z4q40Lf0pROZt1t0fTsNE1qtkTZMkjccLcG4~6J64gBecuNLampYV1LpojQaDTDTg~2r4f6I-5EkNHSWfg~L0IBYRxuLA5FPeirGdYFKjY~A1WvIjfN4pNzmWhwr0dqzeT7qjZ7W33F-7mV5qpQ2uAp95FJRiLLZ9zuy3h0U_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SmileboxInstaller.exe

http://gsf-cf.softonic.com/f1c/8e2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=96059&instance=softonic_br&type=PROGRAM&Expires=1452561101&Signature=AO4GNb9G~KHJ4jGuCVwGS~caXHONdraG~w6zGFEAxK2Tq81w3U~z1UaZw6X7ti8206AY2DPmXr1wJPM20cb8JbppYVnqTsEzPeVpCEJzRLtxshBUG4THleCrQWfRhQmKnGEH7v4Xfhs-1AB0cIr1aiEC8G70iRvDdNmsKqEQzbM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SmileboxInstaller.exe

http://dw.uptodown.com/dwn/FBpxCLy4EXkrO5-8oRCNrvSR7jlWiASrI-9G8xi6asCUu5pksa76eZM_spQTBi_SbBHYmdkCk_1kUmfepQs54-6UTnWTO4fi4jV4tPAnwu23DvwlToHwEIWl58hU0czw/xnxaYh65QwKIrB8-lRLP4FAKoihwk7tCkALDAF2Y47nx1jH3zSYkmYi81fRNt1WrP8HGYL_nMdaInvhqSwkwAm1Pds0Z2TJdAZ5dtvB0nHTkv72fgdePPWAeFB5K0Tdk/.../

https://dw.uptodown.com/dwn/PFUsDKN4asg3jaxO4Lb7MwAv-cYZd8jaYOozHG8u60QAN-xL4rdbYs5np_9K6GHvaZn_n9knrLMXMl31MAIJ9Xryq8_P6_moPWIu2VYLJE-xtMutZyX0ZaC7k2_pQ5gF/EUmol8_4o84j1Mc3JTwq6Vz7LbOK_hvzijEzHtR6-gdPRfbDNWfxsiERvudV2hVvjCKg-YHd_f-7N--lmJFSt0QaEmRDi9Uv1k5mmq9KYl2Jkvk4Diqx7vZC825ywUGA/6t2HAHuZma2UBazYBx2cfCJeeSPmt4Ndw5RrxL2mVgNxGbSR_N6apNKQ4CjDlBui4wd-h7L3EVC2-7zP1EQhLBtcYxQpFv8tfovUhxQTP-cPTUcNX_czVQbHL8WDvUNQ/.../

http://gsf-cf.softonic.com/f1c/8e2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=96059&instance=softonic_br&type=PROGRAM&Expires=1477144889&Signature=enA5X01KbFygEDwBvvplLYOaGX248Ma52UyPAHpATtpNDDqVdcpiEIxuQVNiWFSZS5vWCJy9iIV-6ZorpovDRMKIYrgXAgDb4V3cpmclpNvIeKV4OvtyOqx4K5N5fdd4tRrKTo3CkF4y-MFRla4cAzrXVz6e68tPHXrcw6sK1OE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SmileboxInstaller.exe

http://dw.uptodown.com/dl/1441910972/.../smilebox-.exe

http://gsf-cf.softonic.com/f1c/8e2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=96059&instance=softonic_br&type=PROGRAM&Expires=1457955284&Signature=FxErM86nhLRoO4ITqptU1OOzWzAXogzMeFDK8okyUDmyehfSmAZWIbWPaV7GrnxLAvv-EtllCDqHsICJsm6e9ae1gJeoP0Dy4rilU3hqsqXR5EPiqyafS2vWXOpipIFoBovwZBaU3aGfKCeS1wEMfkV8eGs3SQs7TJMhqPzpSiQ_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SmileboxInstaller.exe

http://gsf-cf.softonic.com/f1c/8e2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=96059&instance=softonic_br&type=PROGRAM&Expires=1461056321&Signature=BKrNT-0tENySlWTtpoWU~q63VQDg1aK5k5K8M9CGc5wzrAuWjePd4OPgsyy~~1Q8Sz2kzFcwYUVRE8yyzL1aAXLbAL-C5PUMjuirNXnJ8DWQKMFJJUWBmyoOoY-Y6o8VH-3QoIK2-FNKTFFJYDjd0M7km2iNqzhY56sSeaMxOcU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SmileboxInstaller.exe

http://dw.uptodown.com/dwn/7EBFPr6RhSGVcRKdbB07BhN_zB0GFXIjROBjMhCm6bpGnREyu3tJjF0_TrFJCr-BiVYATOi-uSvsX3RgGhOMg1bSDmdTBK_jryhHV2yegJoXBGObQnZrlVTPo730WExr/tGBlFyiwa-wVWARIn-L2CLZPnod1ojrDUAVf7bSZDuDFi_tou15YRp1xwvbfiWNoI03xxILo-_ZJDlWU6_INjuNGvPDBF5nE2btLYWQOPeZuD9G5mStHHmLh_eOwjlIj/.../

Scan smileboxinstaller.exe - Powered by Reason Core Security