videoeditmagic.exe

Deskshare, Inc.

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
DeskShare   (signed by Deskshare, Inc.)

Description:
Video Edit Magic

Version:
4.4.5.0

MD5:
2cb1908f156f5ec76422e026de294c73

SHA-1:
ff6ca84081d231459424b46b87e531292057c8e5

SHA-256:
b29068bd2c30f043a18db916a46ddff59901726d26e02368d10a088f84e82bf9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/16/2024 11:17:03 AM UTC  (today)

File size:
13 MB (13,591,704 bytes)

Copyright:
Copyright(c) DeskShare. All rights reserved

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
9/15/2006 3:00:00 AM

Valid to:
9/15/2008 2:59:59 AM

Subject:
CN="Deskshare, Inc.", O="Deskshare, Inc.", STREET=PO Box 769, L=Plainview, S=NY, PostalCode=11803, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00948CB4BB37CF5BD0C4B44E2DF75FADA6

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:a0YQLWLl8kUfN4ceEI1o2jXFeK/M5vl89c9RiQRaNh7Vg:abaWLKvffebN3ovKc9Riiwh7y

Entry address:
0x9A54

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 72, 96, FF, FF, E8, 79, A8, FF, FF, E8, A4, CA, FF, FF, E8, EB, CA, FF, FF, E8, 12, F3, FF, FF, E8, 79, F4, FF, FF, 33, C0, 55, 68, 02, A1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, CB, A0, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 06, FA, FF, FF, 8D, 55, F0, 33, C0, E8, B0, D0, FF, FF, 8B, 55, F0, B8, E4, CD, 40, 00, E8, 23, 97, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E4, CD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.9998

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36.5 KB (37,376 bytes)

The file videoeditmagic.exe has been seen being distributed by the following 24 URLs.

http://gsf-cf.softonic.com/ff6/ca8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=24349&instance=softonic_en&type=PROGRAM&Expires=1476265378&Signature=LMt~vnBZNy7gqL9Oy0V5LPsrChpIZoXjGmL-h6ytfwSwPzvI8ntraxoL9nx-sQSqJAWGJbvfc7lDKuFN6guQBgNhnc0XjvD1hBUIl-loWZjN6RBxQU~eGmnu1mcc984EDF9XlJiafTXvi6vFPYlof7x-rm53h1xwgPUD216UThI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=videoeditmagic.exe

http://gsf-cf.softonic.com/ff6/ca8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=24349&instance=softonic_it&type=PROGRAM&Expires=1455763703&Signature=RVLhptrLDpeNKOqe7PmiGHZgUwqLeoC-pXS7g~56g0qLCznyZyM2IyDwVPXzeitkmsB~M7fh6VGzByVkThl1yrvEV2ywuQ8IAvw0-4nA8d4GnyUk8DfUF3pRAY2v59CMqJjIm0rswxaX4TpUYGgzSHfGc8JLnmQpreQQnhXDNw0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=videoeditmagic.exe

http://gsf-cf.softonic.com/ff6/ca8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=24349&instance=softonic_en&type=PROGRAM&Expires=1472906202&Signature=QiRLLg~Nrk4D0tChWsztcUl8u9qYwEDK~7bn4taCG~12doVwKK~SSwfjyBAxl9LR6CpNVQ-vsT8Fmz5O2opq7RTmPha~R~mm7rYesbnzhFcpdLuFO6GtvyTCAv-os3pzGRl88zusZ7i1ENRW7FW2Jgrw8KAIi6LRKNVMn6~55VQ_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=videoeditmagic.exe

http://gsf-cf.softonic.com/ff6/ca8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=24349&instance=softonic_en&type=PROGRAM&Expires=1446470022&Signature=QGzhyPmywx2t~bj5t3LqkHOgZL8VbmGgBmbDuNVpBYQJ4vCmA1ZFCR0cASETrAJxv1EYrFK41P0l5-DkdTbHOzmSM5hlhigRT-eO2bPuQyxpMrzQcqWu1yDe280rv5drC-0Iya1xwNjxG2uSoaIPIh-TEBU1mB6Rf8AYNdEMOVw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=videoeditmagic.exe

http://gsf-cf.softonic.com/ff6/ca8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=24349&instance=softonic_en&type=PROGRAM&Expires=1459457354&Signature=atiwVzNeQjdfQDmq8-guXaR6T6cIX6jJJ9UudQB~aWF4Upm6~kDfL97WoZ1CeR~yWr3N-Izv-Todpkm6lKEvLGLcwMyanGDRdAc6MXgaLo~IJpC~HG7p0DjwV-cpKwswQSQInv8veGDhFmE5CFnGPoOj6zaAYnLFLAFuv4AdBrM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=videoeditmagic.exe

http://gsf-cf.softonic.com/ff6/ca8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=24349&instance=softonic_en&type=PROGRAM&Expires=1478564170&Signature=DirHWGjiuECu4qdfnIR1T-9eUp2F9urtnbz~j6Sfv~yi5x1BPDBhMxF05~2esmRZwnnrgEMv~svO~6tdUHMpNXh-mg4-CTTrGeoJk-QQNZrWzPXmbIVOur98QaAb5KSU1-itazHLL~rbR44rJBE3IhIvx2~7HnJ8x0WCicdaz2Y_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=videoeditmagic.exe

http://gsf-cf.softonic.com/ff6/ca8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=24349&instance=softonic_en&type=PROGRAM&Expires=1462749560&Signature=L0JrYpb-jCQ1hVL2BFtXWkB8nIC-PIo5P8lkY9pEpq-5pPkt7EneoKNduiPCfTRSEzsrTjPXMZzpv16qzP-SwJsIg22cHYR86QFa7CBmp2sPoAE7lKMLPRuoxUXZITS4uui5PW9AmEhbK7tVt1fv-7rLXdNdvq7uW9v3pYCaUBw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=videoeditmagic.exe

http://gsf-cf.softonic.com/ff6/ca8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=24349&instance=softonic_en&type=PROGRAM&Expires=1472821512&Signature=iGVl4VeXWI3zC0tNoK7eUPcvoQYz9v0PLTiQ988zKeznjHh4dTIxWXH2dymIqIWNzQfk-k8WR~b7Nrs7U2QSp3RlDOfcDlSCYc3BYhU7EAL~SPsc2qQd7QS1qhNe2K-E84-6B0wgqfUIMr4cYfIs5pm5tCT39oWx4EnbeiKYcMs_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=videoeditmagic.exe

http://gsf-cf.softonic.com/ff6/ca8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=24349&instance=softonic_en&type=PROGRAM&Expires=1460014354&Signature=GpBG48dsJQQHCDldFkHKx4lQREtm7w3445Myf4nVqoGOD7kGYPZs-vmDFNIujVOQ0zljUm6MsRuuqeHEE9-3oCYl~R82eVEhosBw-j7OOJDrejG8oG98rwOSPoXr5nERqR7wtkL9xPYjpooqn7EKVQ6nbCLr-0E2U47aHYvqors_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=videoeditmagic.exe

http://gsf-cf.softonic.com/ff6/ca8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=24349&instance=softonic_en&type=PROGRAM&Expires=1450226184&Signature=SKRMzrDBwinhgpUfNODvNeoc~3GHjCipzwzjhVlGwAsOhW~jh7AkwHLKHOxD7dfxW8aAP1PCeyX~s7oFnLk85QFA4WBl9G~2Todq9wU~9eGmxwUcmEq~F2vzm2yVpIbSZ3mTrZOcXt~gn2-oBvRwPNy4PmK3ow1XTau2iGHKu9U_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=videoeditmagic.exe

Scan videoeditmagic.exe - Powered by Reason Core Security