33320578_stp.exe

Nero Self Extractor

Nero AG

This is a setup program which is used to install the application. The file has been seen being downloaded from ftp22.nero.com and multiple other hosts.
Publisher:
Nero AG  (signed and verified)

Product:
Nero Self Extractor

Version:
12.0.3.0

MD5:
a395aa5eb8fc63e4b1a8f69a96aeddfe

SHA-1:
9e1531e02612d1b952ed9599135569ca1d8c907e

SHA-256:
61791cbaa8be52d2e5b8a8d93d5557745e0d98cc79906c72df8dbb2496427f13

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 8:03:14 AM UTC  (today)

File size:
78.2 MB (82,047,856 bytes)

Product version:
12.0.3.0

Copyright:
Copyright 2011 Nero AG and its licensors

Original file name:
NeroSFX.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\33320578_stp.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/22/2012 2:00:00 AM

Valid to:
6/22/2015 1:59:59 AM

Subject:
CN=Nero AG, OU=LEGAL DEPARTMENT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Nero AG, L=Karlsbad, S=Baden Wuerttemberg, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3F5F2725B11E258A905707175244664A

File PE Metadata
Compilation timestamp:
5/15/2012 10:35:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1572864:uLSKBaPM/3DwRIX6SOLd5x3szmABWGOvWmLuIsOyuG:0taP63ERG6Sgb66rO8suG

Entry address:
0x121E37

Entry point:
E8, 6C, 9F, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, 90, 15, 5B, 00, 75, 02, F3, C3, E9, F3, 9F, 00, 00, 8B, FF, 51, C7, 01, 2C, 13, 58, 00, E8, EB, A0, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, CF, D1, F0, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 83, C1, 09, 51, 83, C0, 09, 50, E8, 2A, A1, 00, 00, F7, D8, 59, 1B, C0, 59, 40, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 57, 33, DB, 6A, 07, 33, C0, 59, 8D, 7D, E4, 89, 5D...
 
[+]

Code size:
1.3 MB (1,393,152 bytes)

The file 33320578_stp.exe has been discovered within the following program.

Reader for PC  by Sony Corporation
Publisher's description - “Read all of your favorite eBooks, Newspapers and Magazines from Reader's Store on your PC. Sync your Reader Store content across your PCs, Macs and Android devices. Access all your favorite eBooks, Newspapers and Magazines from Reader Store.”
www.sony.com
3% remove it
 
Powered by Should I Remove It?

The file 33320578_stp.exe has been seen being distributed by the following 10 URLs.

http://ftp22.nero.com/.../Nero_BurningROM2014-15.0.02100_trial.exe

http://www.tamindir.com/indir/MjAxMy0xMS0xMCAxNDozNzo1Mg==/nero/.../15.0.02700

http://ftp22.nero.com/.../Nero_BurningROM2014-15.0.02800_trial.exe

http://server3.xnavigation.net/dl/Tvbzj/61/13984/defa/.../nero-burning-rom

Scan 33320578_stp.exe - Powered by Reason Core Security