srware_iron.exe

SRWare Iron Setup

SRWare

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
SRWare

Product:
SRWare Iron Setup

Version:
36.1950.0

MD5:
69a1f7cab8f2fd24c1377ecc12187e04

SHA-1:
39aa942d19a46655f5daa0f504f49d0508a4dc00

SHA-256:
c79b58a7784f33a039091c14e13decd70c6ee1e5bc01e82da92b8d8241609bf2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/16/2024 7:39:31 AM UTC  (today)

File size:
40.1 MB (42,019,725 bytes)

Product version:
36.1950.0

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\srware_iron.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
786432:FyGwerD056Dm11QbmNDZGbFe5tBHe1rfZzWD/IePf7srEa62Pcf7:FyGwerD056Dm1qbyZyQb0ZqD/NPfgYVb

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file srware_iron.exe has been seen being distributed by the following 4 URLs.

http://dw.uptodown.com/dwn/DT4fPphnS87t5drJtQTZ4XkXlH6NYd4wBIVUgwc39Y5wFKcLentiCfhmFuLGf-Ye7fJmKrHH0VSy7_NqUBCEX27l6SfjUyLUi49TFzBTPfZ8Wq-OslB_Ki44CYp3Zytf/VefS4Ekd9Hbrkn2PtpasFi-XuBl2YtaiqOtgfSg9PRHzC3-XPximqvSF4FpdvPrwzczLFSSqRLuvI19Nr6iQh5WXdSy5M67C2hayRcK8LmsiYBy5z6ntQNRnql742V-1/CQJgjt_mybWiJGmIjom9NL7Mp9t-BN8bbuVvxODKVmJdp_axSXKfPq5-_g-av-Js9QbYGjinxpOk_Le9GdK8Wes1rSRDfgk0RuU-OBVbpcfoifVd2MMS3xkZ-fS5FIN3/.../

https://dw.uptodown.com/dwn/TfG4R_c1om78cop3KjMCcWhLXZneyetqq2cDshWc09rbNBWK-u_fPdMMnbE3gAB7kIBjZJQ0Lj8jimtNN3Mfgh7lqKtXMV-897_V11KOlBCs7jWBbcbOUeL7WoyZyxb7/UoYIcSlag08zV5h91j4edgalZ0hxaIyHZLZCcatAIZNcgaLBKpDhlj3_xyp24BUSjMYK2wSvJOnwD8rI-o-iustMK3YSPRoJnN5vyLW-cC3ScM1b5HjSgMA51txY5m9-/oIN6FX399BtKhfWzPIi0IS80kgWMkCUb6mvkKcw9dxdJwfz_-HmuO_XG5n9m2ZMi-G323sybH1V5rpJxn5FWM6ZEaHbqtZ7avGpcghhz1Ricd3Yy3OdDsXk9EzdCazag/.../

Scan srware_iron.exe - Powered by Reason Core Security