text2gosetup.exe

Tumbywood Software

This is a self-extracting archive and installer. The file has been seen being downloaded from www.text2go.com.
Publisher:
Tumbywood Software  (signed and verified)

MD5:
f422abadf03a537bff7ef53f9604279e

SHA-1:
a12ce6d88d2827b1a8c97890d9b98078483a7e45

SHA-256:
5afb09475c0eaa7bdf5858b433267437b3c64a896ca044ede3ae94c6ee751611

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 5:27:13 PM UTC  (today)

File size:
8.1 MB (8,462,088 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\text2gosetup.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
8/17/2009 7:00:00 PM

Valid to:
8/18/2011 6:59:59 PM

Subject:
CN=Tumbywood Software, O=Tumbywood Software, STREET=13 Cooinda Crt, STREET=Frankston South, L=Melbourne, S=Victoria, PostalCode=3199, C=AU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
0BD0C176A7947264A16AC349D1941C50

File PE Metadata
Compilation timestamp:
7/23/2007 12:30:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
196608:KYHxYbWRP0Ga4nc1LPadS4Kx6ookCYg/tcOx4Kp3PH:K4xYbicLlfNokPglcOxdfH

Entry address:
0x7EB8

Entry point:
E8, 19, 28, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 10, 75, 20, E8, A4, 15, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 35, 15, 00, 00, 83, C4, 14, 83, C8, FF, E9, 80, 00, 00, 00, 8B, 4D, 0C, 3B, CB, 56, 8B, 75, 08, 74, 21, 3B, F3, 75, 1D, E8, 75, 15, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 06, 15, 00, 00, 83, C4, 14, 83, C8, FF, EB, 53, B8, FF, FF, FF, 7F, 3B, C8, 89, 45, E4, 77, 03, 89, 4D, E4, 57, FF, 75, 18, 8D, 45, E0, FF, 75, 14, C7, 45, EC...
 
[+]

Entropy:
7.9969  (probably packed)

Code size:
60 KB (61,440 bytes)

The file text2gosetup.exe has been seen being distributed by the following URL.

Scan text2gosetup.exe - Powered by Reason Core Security