winzip165.exe

WinZip 16.5

WinZip Computing

This is the installation and setup package for WinZip, a file compression/decompression utilitiy that has a GUI to zip interface. The installer might bundle additional software offers during setup including the AVG browser toolbar. This is a self-extracting archive and installer. The file has been seen being downloaded from c10891052.r52.cf2.rackcdn.com.
Publisher:
WinZip Computing  (signed and verified)

Product:
WinZip 16.5

Description:
WinZip 16.5 Setup

Version:
1,18,0,2570

MD5:
8bcdccb5559ab54d393fa75e6539fd63

SHA-1:
0f368ad199ddf108df8e9f3d0cfd503a50df2c03

SHA-256:
6b9711a6c10c4a33272a610a8a06742e970bd63c580b11dec62336572c01e689

Scanner detections:
9 / 68

Status:
Clean  (9 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/25/2024 1:08:25 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Rogue
7.1.1

Bkav FE
W32.Clodfcb.Trojan
1.3.0.4959

Emsisoft Anti-Malware
Trojan.Win32.OpenInstall.AMN
8.14.06.18.10

ESET NOD32
Win32/OpenInstall (variant)
8.7187

MicroWorld eScan
Win32/OpenInstall
15.0.0.507

Sophos
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-OpenInstall-Winzip
10536

Trend Micro House Call
TROJ_GEN.F47V0831
7.2.169

Vba32 AntiVirus
Trojan.Agent
3.12.24.3

File size:
348 KB (356,328 bytes)

Product version:
16.5

Copyright:
Copyright © 2012

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\winzip165.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/16/2012 12:00:00 AM

Valid to:
4/14/2014 12:59:59 AM

Subject:
CN=WinZip Computing, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WinZip Computing, L=Mansfield, S=Connecticut, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E4842AC9691630B45F8266C0ADB1206

File PE Metadata
Compilation timestamp:
5/29/2012 3:49:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:WVhlAMCF4rJXgVf0CNQKCorZFObQbFh3UV4CafGgAeUjTrYmpSgxLqs2TT+jU:u8MC+OPN0+ZFOMbEWCaegKHYmpXxvWTT

Entry address:
0xE80A0

Entry point:
60, BE, 00, 50, 4A, 00, 8D, BE, 00, C0, F5, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.6821

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
272 KB (278,528 bytes)

The file winzip165.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to oi.cloud.avg.com  (204.193.144.33:80)

TCP (HTTP):
Connects to inst.avg.com  (204.193.144.89:80)

Scan winzip165.exe - Powered by Reason Core Security