va_x_setup2108.exe

Whole Tomato Software, Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from www.wholetomato.com.
Publisher:
Whole Tomato Software, Inc.  (signed and verified)

MD5:
474ad1418d11a352d89be04756ddd7a4

SHA-1:
e26af6ce53a468d9da90cde048f842e2910b0fe4

SHA-256:
f74b225fc6b17051e3df65b5594522e264c4cd6215d80c061c05d1dc2b98bc97

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/2/2025 7:34:05 PM UTC  (today)

File size:
21.9 MB (22,964,552 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\va_x_setup2108.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/18/2015 3:00:00 AM

Valid to:
8/7/2017 2:59:59 AM

Subject:
CN="Whole Tomato Software, Inc.", OU=Secure Application Development, O="Whole Tomato Software, Inc.", L=Englewood, S=Florida, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
51F6066269CB336D1EC5A687D8EE99E9

File PE Metadata
Compilation timestamp:
8/2/2016 6:00:33 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
393216:XyfoO1Xp9nxQcAW8hFig0wJvdB5SST00JMDB+x8z5+Cg23M8wQvUiT:CfoO1pRxMWMQHkvdXzTLK+/pSnwsDT

Entry address:
0x6034

Entry point:
E8, 9E, 05, 00, 00, E9, 80, FE, FF, FF, 55, 8B, EC, 6A, 00, FF, 15, DC, 80, 41, 00, FF, 75, 08, FF, 15, D8, 80, 41, 00, 68, 09, 04, 00, C0, FF, 15, 5C, 81, 41, 00, 50, FF, 15, E4, 80, 41, 00, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, EC, 04, 01, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, B8, 2A, 42, 00, 89, 0D, B4, 2A, 42, 00, 89, 15, B0, 2A, 42, 00, 89, 1D, AC, 2A, 42, 00, 89, 35, A8, 2A, 42, 00, 89, 3D, A4, 2A, 42, 00, 66, 8C, 15, D0, 2A, 42, 00, 66, 8C, 0D, C4, 2A, 42, 00, 66, 8C, 1D, A0...
 
[+]

Entropy:
7.9917  (probably packed)

Code size:
90.5 KB (92,672 bytes)

The file va_x_setup2108.exe has been seen being distributed by the following URL.

http://www.wholetomato.com/.../getBuild.asp?2108

Scan va_x_setup2108.exe - Powered by Reason Core Security