vuex6492.exe

VueScan Installer 9.2.24

Hamrick Software

This is a self-extracting archive and installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Hamrick Software  (signed and verified)

Product:
VueScan Installer 9.2.24

Description:
VueScan Installer

Version:
9.2.24

MD5:
8bf2a8c7eae0523faeeea3d1acbc8cd3

SHA-1:
ef6d67106811fbbf6e9adcfc44e89338b87c22ce

SHA-256:
ffbc00c75cf9b710f1808782ef1296a720a30a6df03127d78a66869e916620b2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:55:27 PM UTC  (today)

File size:
8.5 MB (8,920,320 bytes)

Product version:
9.2.24

Copyright:
Copyright 2013 Hamrick Software

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/31/2013 8:00:00 PM

Valid to:
6/30/2016 7:59:59 PM

Subject:
CN=Hamrick Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Hamrick Software, L=Phoenix, S=Arizona, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
233F0EC1E12F897C28D1CA013251744C

File PE Metadata
Compilation timestamp:
9/8/2013 1:38:40 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:/RynOEbel4hUNQt3MMbpXLWR3M2C6+swhzVKdjmXUkcGcsoT+zz:/Ryn/hUNk33Fvqnwlz

Entry address:
0x6E91

Entry point:
E8, 87, 57, 00, 00, E9, 89, FE, FF, FF, 66, 0F, EF, C0, 51, 53, 8B, C1, 83, E0, 0F, 85, C0, 75, 7F, 8B, C2, 83, E2, 7F, C1, E8, 07, 74, 37, 8D, A4, 24, 00, 00, 00, 00, 66, 0F, 7F, 01, 66, 0F, 7F, 41, 10, 66, 0F, 7F, 41, 20, 66, 0F, 7F, 41, 30, 66, 0F, 7F, 41, 40, 66, 0F, 7F, 41, 50, 66, 0F, 7F, 41, 60, 66, 0F, 7F, 41, 70, 8D, 89, 80, 00, 00, 00, 48, 75, D0, 85, D2, 74, 37, 8B, C2, C1, E8, 04, 74, 0F, EB, 03, 8D, 49, 00, 66, 0F, 7F, 01, 8D, 49, 10, 48, 75, F6, 83, E2, 0F, 74, 1C, 8B, C2, 33, DB, C1, EA, 02...
 
[+]

Entropy:
7.9970  (probably packed)

Code size:
64.5 KB (66,048 bytes)

The file vuex6492.exe has been seen being distributed by the following 19 URLs.

http://gsf-cf.softonic.com/ef6/d67/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44180&instance=softonic_es&type=PROGRAM&Expires=1476433848&Signature=irN3CVc3Gc3tr0RrCLtSUrmkgUvGxf4ettI0iRSgGSD7o2O3rLyymTCqJoeYt4q57Lt3Ad4Xk7wvdlvURGgkW58s9hQn4t15kt73qSbl8dmwdHFBkG6I-MfDo4exrTOMRhveKuSxzmiJtLl6MFXvfGKd-SpN-WUoLqkLdCVJ9jU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=vuex6492.exe

http://gsf-cf.softonic.com/ef6/d67/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44180&instance=softonic_es&type=PROGRAM&Expires=1446647307&Signature=dp9bU0MR8lnGhegH6LbKGEYzYKclENNOe86duevtkmp5xXfvqXJn16hff9l6s65lthF9GJquWVlMA0~OecuCxPFJ6~w0H~BYEQv4FKsAbrGk3tpRoI0L72C4vscBMhW6CMI0SoMiXCiwK3axYWgXPoLA9fMf8lEBIRyKrzxy708_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=vuex6492.exe

http://gsf-cf.softonic.com/ef6/d67/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44180&instance=softonic_es&type=PROGRAM&Expires=1467017424&Signature=XwxczPnL8cqJIW78kOVRQlyjzKcurGfF3ABfzZBPU4KjXhIzU03eqh7Nl~Voae~PAyrI9BIzU9x6C3MfBSsXnxLyaEcB4D9QxFhLQpghtk7slZz2fESA3s5sTNGCO8pNVFCaUSHHIiLl2zyVXPZhaXB8PK28E4wv6hiWzw3vopE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=vuex6492.exe

http://gsf-cf.softonic.com/ef6/d67/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44180&instance=softonic_es&type=PROGRAM&Expires=1425911617&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=X0NwNWG1qr0U7UjMR8sJVKR37V1ToSFaXJYQ6OTWEKx2jk953v5QDtyKYmqY3Pmo2STlhFQB6H0g4rvxU-a8tvn~LkT3IEY~To40DlrgHYCR0UKZ5l4cDQcMkabfjdaQaADV14Dful~q1p42fgQHSBLuQ9hc6vB-QtVf8dvOvl4_&filename=vuex6492.exe

http://gsf-cf.softonic.com/ef6/d67/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44180&instance=softonic_es&type=PROGRAM&Expires=1470483299&Signature=emyRyewQxomMcGERjBbfZkoeK0IPqSz27s-jbThwiG-pqfnA~So8iGCau6HddicjweKUa09wubZGMr7wg4KU0E6J~RZnQC-pZhAvTh5-ixExUmEl19WAuzO9b8qWbyEI5sdE6It8hUlfwoCneUSMBdUwLYFVUmk1OSLXIKUkWSc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=vuex6492.exe

http://gsf-cf.softonic.com/ef6/d67/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44180&instance=softonic_es&type=PROGRAM&Expires=1472965433&Signature=NtZafme0p-56TbU2TcGu6W0mxu1M0qB2vJRxv8bZs9gcuaQrMrUEuVLAfXup2y2WWhvxo4lhS61prAmztEarsPcHdzdEkhsLMgXH2Bv~xSo8knQYSQ7ASx61qDWaAqtZzSzeGtV8FTg2D22WogQ8der-FBnoW84Hso~gvUxAWTQ_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=vuex6492.exe

http://gsf-cf.softonic.com/ef6/d67/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44180&instance=softonic_es&type=PROGRAM&Expires=1461921866&Signature=Isu7cuwrgHrhIGSKM8JKvrYKDrObU7oze7IFo8W2-2CVqjwxSfJGIoWgQvk9b9Cactx6SFvJX3xjUDraZtE6JWxaxoAblEkEJwBfo9Jz-PtppKuhuJsYcsLN3XSA1Thsry7vspiwMRKHPXpANlGgLwXXwSaG3nIp-AbJaLh5hqE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=vuex6492.exe

Scan vuex6492.exe - Powered by Reason Core Security