Suspicious winzip installation file.

Yesterday i tried to install winzip program and downloaded install file winzip21-home.exe from official site http://winzip.com/win/en/index.htm via “Try it free button”. Installation process went ok, but i couldnt find winzip program. So i checked downloaded file and find that i downloaded it from site winzipmain.com and not winzip.com. I had avast installed and it did not blocked the download link nor the file itself, afterward i ran avast scan but it didn’t find anything worrying. Could you tell me if that is really winzip installation file and my system is not compromised? Thanks.

Download link, that I used:

http://www.winzipmain.com/UDFXUutCqMts_zZYfOhAjopJ9JbNqLwfk0ufdwcqsS61L7jzX0LjXaAX8OjaXUIHVrSfMtXiWLkxmM5GH036mENWz6m4_lZN2lloX1iRmIrqsHIfWfTMSkOUoXhAzcMyvI8YclY1Scxj+7f3bDSgim_KP942TmR9BJec1pkjZY1xp3rQz1KyenBhh94UZ+fSujxkxFdZrpJjZtHAA4KiCpKKTX5UUR3qtmZgXRbhEab7bFCuZDncx0IpB7oQ20AIg41+ZAI46_Plu_DF8Dzp0AH5M4bT6uijPu2JeX_Vi4X7Cb4eg5Q2gvZwe429ZKteUSswfB_EL3kNI3HZ1NgETpoOFgl8SXVGjeoJnRqp941d2W07qGWlbRWMOaItv19nYmxL1_z7g0GAX9_Zfa7ld1wpknOc2A==-GzMAAERveF6I85dEy0dgAw6cSuAF12Fj7ByHIES8saLlTXxO0kULqiG4pjSK+Dk=

Blacklisted by Bitdefender
https://virustotal.com/en/url/207c246f940c51f78e91d1a18b232af5bd3d6354c624e645e3c3425ad70b1490/analysis/1483460460/

Infected by two engines
https://virustotal.com/en/file/304cf2ae7560a9749cd4576fa6de0224f87cfda2e5936083b4c419c11cd24e8d/analysis/1483000481/

Authenticode signature block and FileVersionInfo properties

CopyrightWinZip
Product WinZip
File version 1.0.11.60897
Description WinZip
Comments This installation was built with Inno Setup.
Signature verification Signed file, verified signature
Signers
[+] WinZip Computing LLC
[+] GlobalSign CodeSigning CA - SHA256 - G2
[+] GlobalSign

First submission 2016-12-29 08:34:41 UTC ( 5 days, 7 hours ago )

Seems like a false positive

I think that winzip.com was hacked.
Now button “Try it for free Win 10/8/7/Vista” from winzip.com links to http://www.winzipsoftware.com/1ycak9cJzsDvQGQfRljmYKl8Xb+JKsVAaCU7wh7KttIaORSF3+qPBDLgfUY5gHVaR0aF21LIApB+xNMGsJ1EQFof3zg0hLBts38GWzqAFi8y3fy8MFD0SxGe5a63CsTK8Bu241QpYjFtI11sQ5TRJ8wxkpQ2QvwM32Z+R_ry_E8yKauFPbpGSPAT8LECbImfnOy71eJ8vzInOeBX5zenrX6vY5GToMwKQDqo4N1W0IJKOTucUD1nXImg_JscPiUnPOW8p+XCbRnoIoCrHzHXGazSyqIfuo3VT5EuLRRXUXZAF57_25a0JqZQb_VJJOSbcvzHYpts1NpfPtOgfkYYoac35ExzjnqMgVLhAnLzDJ44mdwV92q7JEW3ZqY8DYPvAZPvW4XV7wg+HPeqRegGlgU9YONC0w==-GzMAAERveF6I85dEy0dgAw6cSuAF12Fj7ByHIES8saLlTXxO0kULqiG4pjSK+Dk=

And the link changes every time you enter the winzip.com site.

The file that comes down now has a different SHA256 / MD5

https://virustotal.com/en/file/e6b6ae1ecd03df8e855073d23145a1439483b52f6d060a573dc3a0eff51f151a/analysis/1483461197/

https://virusscan.jotti.org/en-US/filescanjob/hah68zx7gm

First uploaded 2016-10-31 09:01:44 GMT / Last scanned 2017-01-03 16:39:08 GMT
https://www.metadefender.com/#!/results/file/bzE3MDEwM3JKV2xoUUl0U2xIeWZ4blFJdEJl/regular/analysis

https://virustotal.com/en/url/207c246f940c51f78e91d1a18b232af5bd3d6354c624e645e3c3425ad70b1490/analysis/1483460460/

Sendt the URL to F-Secure for check (they use Bitdefender blacklist) and this was the reply

Thank you for your submission.

Our analysis has found that the URL submitted is not harmful. The rating of the url will be updated.
The updated rating will take effect automatically via Security Cloud otherwise known as ORSP.