advbc.exe

Belltech Systems, LLC

This is a setup and installation application. The file has been seen being downloaded from global-shared-files-l3.softonic.com and multiple other hosts.
Publisher:
Indentsoft Software Solutions   (signed by Belltech Systems, LLC)

Description:
Indentsoft Advanced Business Card Maker 3.0 Setup

MD5:
ae078625692db14a1cbf0d470cfa7bd3

SHA-1:
183714972ab5c3bf32cd401cf97ffe2acd96f729

SHA-256:
9f222c57b60404d5bbe6b2ddb7e51a31cc424a05250ece439423212c60be14ef

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 6:05:12 PM UTC  (today)

File size:
4.9 MB (5,110,920 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/5/2004 7:00:00 PM

Valid to:
12/6/2005 6:59:59 PM

Subject:
CN="Belltech Systems, LLC", OU=Technology, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Belltech Systems, LLC", L=Issaquah, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
74576C42D45F19B05FBD785FBE2ACA55

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:JPsuO15Jnh8s96WRRgKaQMHSalNXHaVBkFiThv8QFPmc9+:JtK5Jh3TDyHSalNX6oFSKQtZ+

Entry address:
0x9264

Entry point:
55, 8B, EC, 83, C4, B8, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, BC, 89, 45, B8, E8, 5F, 9E, FF, FF, E8, 8A, B0, FF, FF, E8, E9, D2, FF, FF, E8, 30, D3, FF, FF, E8, 07, F6, FF, FF, BE, CC, BD, 40, 00, 33, C0, 55, 68, 14, 99, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, A4, 98, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, EC, FE, FF, FF, E8, 9F, F9, FF, FF, 8D, 55, F0, 33, C0, E8, 41, D6, FF, FF, 8B, 55, F0, B8, C0, BD, 40, 00, E8, 10, 9F, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, C0, BD, 40, 00...
 
[+]

Entropy:
7.9989

Developed / compiled with:
Microsoft Visual C++

Code size:
34.5 KB (35,328 bytes)

The file advbc.exe has been seen being distributed by the following 11 URLs.

http://global-shared-files-l3.softonic.com/183/714/.../file?nvb=20141126191347&nva=20141127071447&token=01900dd1943099f2ec20f&instance=softonic_fr&filename=advbc.exe

http://gsf-cf.softonic.com/183/714/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44628&instance=softonic_en&type=PROGRAM&Expires=1477071098&Signature=dtmr3Zk5dcoj2jW~eBSdZJNTTxaqoEmPEqfTUzsIFVuIKprGe0mOaeSEaG-no-FyCCBj5vfGTaSpID0Lkt2pgBcAD6bdGl0xkguvipnugKDd31PzftJunl7ER~UIKcYNdxWLmTPuKOQyPsVNJE1Q9Rj-aDbuOzh5SOyy7Pj0Bz4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=advbc.exe

http://gsf-cf.softonic.com/183/714/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44628&instance=softonic_en&type=PROGRAM&Expires=1478485722&Signature=HjwlkV-xaFHRXjwYHJNAYL7QtLb7Fyb7yLSB0P2unFoFgYYgxg4wfq0bNIjip~MVoELGMG-OXwwgKtRQxHTN5dlsNCEaIyc-GFdcSEhFLWUr2kIetWfOVEBXjeSibHmPjJwe146x0w-Dfuk4-8sQ7zf9uIBW0iyrU1ogsDobpeE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=advbc.exe

http://gsf-cf.softonic.com/183/714/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44628&instance=softonic_es&type=PROGRAM&Expires=1446625813&Signature=E3ijJ~0gauuNd5YQgzWCSHylRQRKJwkg0LxtgyYMTnXANULJzt4339oCYebOmxcOGLSUyFvwdRp14G75MWDrwzJXsmz5EmwSUbZqyVM-pSw1KN4FRfccNOFp5nND7T3ScT-5zdPG-Dh8mKi9FEFzaYyfBQBAY1-yJFCZxfc0huQ_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=advbc.exe

http://gsf-cf.softonic.com/183/714/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44628&instance=softonic_en&type=PROGRAM&Expires=1473347438&Signature=d~g9LA3TjdrYvCIyoX67IgXLxx5IDzOfxwWqKFBZzxRMElu4MDQ569g3kIaGJXV41lHFG~f1H96zSWmVaDiDvYBpjF9qzUZMpP7PUeHMgJvM9lIIUdNwMdeZDC8YUHQedjmIRH77w-KOaJDm0qF~RGxk2VB5irkad292nQG~3Dg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=advbc.exe

http://gsf-cf.softonic.com/183/714/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44628&instance=softonic_en&type=PROGRAM&Expires=1429187607&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=gu~W180mwScnp7iNDM2XKGp0XP4q-lmUci2m3RkbXNGMoBZjKPhXySn9s1jSu~l43U12BmGiK~-Wd8~-Tr7uJFeRTPFd6MPUeWMivjAfwgl2oCOKJhtQKZHURRBzvTIjIBG6tTPrSr26QGKmSc8VpUWHyNURh2ucD57B-F1~D0M_&filename=advbc.exe

http://gsf-cf.softonic.com/183/714/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44628&instance=softonic_pl&type=PROGRAM&Expires=1458026306&Signature=AXDA89C0rvdod3bw5LKjyMSXwKUyBV48KwOWQX02LPwYfTHOl9ewPKRvXc9kU5lsng-SmaZmkIfQcom9RCQ8nfsjkTWr8h1QB-SqYTC58OZvdrEGNinU-wedoh74Dv981FWdyUqPORmBZ-GzzFLm29VH1GGrbM-Qe~mCyGPzzjE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=advbc.exe

http://gsf-cf.softonic.com/183/714/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44628&instance=softonic_en&type=PROGRAM&Expires=1457968379&Signature=UfI2HIhCx8DJO6OYMm3QHagFXjn6uxJglfNGXgDcpkiHrQ8tbVNhs~XDkd48TdizvBNXQNipWcCQcZ2wqprrCzUZ1PN79zrciez-RMJEDn-FQ-o9CJBr-Y~o3YtiFibvu1Vpm6WqDFgYGOMNerLez4BwUBpROIapRzjSGKZYRd8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=advbc.exe

http://gsf-cf.softonic.com/183/714/.../file?SD_used=0&channel=WEB&fdh=no&id_file=44628&instance=softonic_en&type=PROGRAM&Expires=1457309105&Signature=h5Ka2cAoaTuCXilMLvsxIYEaPD0RqtDV6k3sMbMKDja4RF1aBNBuWv82880DsnfCWQvk7S~sfIplfro4rJ9cpM9-NYAG90EIA6YpvSQwFAw2FbyzbqJZzSozkApQK9agY9NlXRL1EwG1Oq7Sssgpma2ARf~L9EwQ4xm-Uhp~zqc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=advbc.exe

Scan advbc.exe - Powered by Reason Core Security