download-(support+heroglyph-2.0)-heroglyph-25-demo.exe

proDAD Application Downloader

proDAD GmbH

This is a setup program which is used to install the application. The file has been seen being downloaded from esd.element5.com and multiple other hosts.
Publisher:
proDAD GmbH  (signed and verified)

Product:
proDAD Application Downloader

Description:
Download files from www.prodad.com

Version:
1, 0, 0, 1

MD5:
af0b8e212a170995994319d025157caa

SHA-1:
95b97f81fad4fef5042feaffbcb3e92243f87ffd

SHA-256:
157b3c0991c5cfda41b414eec807ad2dff82f1160cae70ba720046fdbdc45a2c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 8:04:30 AM UTC  (today)

File size:
389.6 KB (398,912 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2008

Original file name:
FileDownloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\download-(support+heroglyph-2.0)-heroglyph-25-demo.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/26/2007 9:01:47 AM

Valid to:
2/26/2010 9:01:47 AM

Subject:
E=webmaster@prodad.de, CN=proDAD GmbH, O=proDAD GmbH, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
01000000000110FCDAE00C

File PE Metadata
Compilation timestamp:
11/12/2008 9:47:43 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:N2ccQHJcDOaIsVObVKnIKk5mXemm73ojDuUlPd:NoOz6OgnIKMeDuUll

Entry address:
0x148E4

Entry point:
E8, 1D, 57, 00, 00, E9, 17, FE, FF, FF, B8, 27, AB, 41, 00, A3, 74, C1, 43, 00, C7, 05, 78, C1, 43, 00, 23, A2, 41, 00, C7, 05, 7C, C1, 43, 00, E1, A1, 41, 00, C7, 05, 80, C1, 43, 00, 15, A2, 41, 00, C7, 05, 84, C1, 43, 00, 8B, A1, 41, 00, A3, 88, C1, 43, 00, C7, 05, 8C, C1, 43, 00, A1, AA, 41, 00, C7, 05, 90, C1, 43, 00, A1, A1, 41, 00, C7, 05, 94, C1, 43, 00, 0B, A1, 41, 00, C7, 05, 98, C1, 43, 00, 9A, A0, 41, 00, C3, E8, 9B, FF, FF, FF, E8, 74, 62, 00, 00, 83, 7C, 24, 04, 00, A3, 0C, F2, 43, 00, 74, 05...
 
[+]

Code size:
176 KB (180,224 bytes)

The file download-(support+heroglyph-2.0)-heroglyph-25-demo.exe has been seen being distributed by the following 6 URLs.

http://esd.element5.com/affiliate.html?affiliateid=73840&publisherid=50860&target=http://demodl.element5.com/.../Download-(1)(support files)-adomm02demo.exe

http://esd.element5.com/affiliate.html?affiliateid=200086180&publisherid=50860&target=http://demodl.element5.com/.../Download-(1)(support vitascene)-vitascene-10-demo-ltd.exe&ClickID=bylzzknm1mfemn6u1emzqmvf1m6gvyfllqvn