vsinstall.exe

header

Paul Sanders

This is a self-extracting archive and installer. The file has been seen being downloaded from static.letoltokozpont.hu and multiple other hosts.
Publisher:
AlpineSoft  (signed by Paul Sanders)

Product:
header

Description:
AlpineSoft Installer

Version:
1, 0, 0, 1

MD5:
e60be8d4d628f8a1f35254ce0cf90191

SHA-1:
c2aac468d9f371429ae6db035c39a3878e6241a4

SHA-256:
416da63ad2bdc3573f7f1e9a9a0096cebbb943f0359e8fddaf6722b5e324f90a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 11:50:54 PM UTC  (a few moments ago)

File size:
3.6 MB (3,793,048 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2007

Original file name:
header.rc

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\downloads\vsinstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/11/2013 2:00:00 AM

Valid to:
4/11/2016 1:59:59 AM

Subject:
CN=Paul Sanders, O=Paul Sanders, STREET=27 Buffins, STREET=Taplow, STREET=27 Buffins, L=Maidenhead, S=Berkshire, PostalCode=SL6 0HF, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00AFC39A821A53551AD1B677DD5112AADA

File PE Metadata
Compilation timestamp:
6/17/2010 8:05:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:FIeSpP2hxPvtElRQOnCoXAl/bm+iMHZhAJ3pO6RazRi+p:FIaTOCBDm+iuv6gs+p

Entry address:
0x3F53

Entry point:
55, 8B, EC, 83, EC, 44, 56, FF, 15, A8, 80, 40, 00, 8B, F0, 8A, 06, 3C, 22, 75, 11, 3C, 22, 74, 1D, 46, 8A, 06, 84, C0, 75, F5, 3C, 22, 75, 13, EB, 10, 3C, 20, 7E, 0D, 46, 80, 3E, 20, 7F, FA, EB, 05, 3C, 20, 7F, 07, 46, 8A, 06, 84, C0, 75, F5, 83, 65, E8, 00, 8D, 45, BC, 50, FF, 15, A4, 80, 40, 00, F6, 45, E8, 01, 74, 06, 0F, B7, 45, EC, EB, 03, 6A, 0A, 58, 50, 56, 6A, 00, 6A, 00, FF, 15, A0, 80, 40, 00, 50, E8, C8, FE, FF, FF, 50, FF, 15, 00, 81, 40, 00, CC, 55, 8D, AC, 24, 68, FE, FF, FF, 81, EC, 18, 02...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
25.5 KB (26,112 bytes)

The file vsinstall.exe has been seen being distributed by the following 2 URLs.

http://static.letoltokozpont.hu/letoltokozpont.hu/programok/.../VSInstall.exe

Scan vsinstall.exe - Powered by Reason Core Security