install_pdfr_v224.exe

PDF reDirect

EXP Systems LLC

This is a self-extracting archive and installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
EXP Systems LLC  (signed and verified)

Product:
PDF reDirect

Description:
Install program for PDF reDirect

Version:
v2.2.4

MD5:
9353d108c3a62756239fd2ec58595078

SHA-1:
30a15faa7f37c1cd59c40fb04b4c77f75b1e7ef0

SHA-256:
efbc8a909f94b1fa9e5ca3380da9d97193d603fd45bab1e66ad7ff6f4debee41

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 5:33:41 PM UTC  (today)

File size:
5.8 MB (6,129,168 bytes)

Copyright:
©2007 EXP Systems LLC

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\install_pdfr_v224.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
2/20/2007 1:00:00 AM

Valid to:
2/21/2008 12:59:59 AM

Subject:
CN=EXP Systems LLC, O=EXP Systems LLC, STREET=11058 W 1st Street CT N, L=Wichita, S=KS, PostalCode=67212, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00BFFD1D4A80E153323903E9BFA60ACB76

File PE Metadata
Compilation timestamp:
2/4/2005 3:07:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:of7gc7v5EprNHNTIs1CvbL2G6X5exlNjCqPs3b+sHZ8/5/GYngfK8ADOe:o0c7v5EFNHNUVTL2lpZq868t2DOe

Entry address:
0x3E27

Entry point:
83, EC, 20, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 68, 91, 40, 00, C6, 44, 24, 14, 20, FF, 15, 28, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 68, 88, 92, 40, 00, 68, 40, 3B, 42, 00, A3, F0, 43, 42, 00, E8, D8, 27, 00, 00, BE, 00, B4, 42, 00, BF, 00, 04, 00, 00, 56, 57, FF, 15, C8, 70, 40, 00, E8, 7A, FF, FF, FF, 8B, 2D, 8C, 70, 40, 00, 85, C0, 75, 21, 68, FB, 03, 00, 00, 56, FF, 15, C4, 70, 40, 00, 68, 80, 92, 40, 00, 56, FF, D5, E8, 57, FF, FF, FF, 85, C0, 0F, 84, 47, 01, 00, 00, BE, 00, A0...
 
[+]

Code size:
22.5 KB (23,040 bytes)

The file install_pdfr_v224.exe has been seen being distributed by the following 19 URLs.

http://gsf-cf.softonic.com/30a/15f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=40709&instance=softonic_en&type=PROGRAM&Expires=1482332332&Signature=iqrocZmGgnlqys-kKSyCMMSL5ymlKOciADfmCHh3OyeRcgBRrIdph11WsXyiezn6ywFOJTjJ~q~y375X5OjeN~S0g4N4s4AU2FfuhxilsA5iOM5knQ-wT5tMwuOFCZvaxnNdeVBnYVOptWHd4qG0iyN84z7C1iSTuGvRwVcMlAc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Install_PDFR_v224.exe

http://gsf-cf.softonic.com/30a/15f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=40709&instance=softonic_br&type=PROGRAM&Expires=1479351949&Signature=L~2FpOppJWZeMOf7fa0TEwTkZXdNc2C3ANTU2twyaVBj6KNGyOwZamZLj2E0m4k4hGjtNZnxGAS5yD8cuaJrJHKnoPS2oClm-7Y3yejRdh46RVZBRkkdzkl1T-jmvwFk1IvLRho7caEPaaD2NOs3x7ZGxn6OnUPFDIzgIib5xt0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Install_PDFR_v224.exe

http://gsf-cf.softonic.com/30a/15f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=40709&instance=softonic_br&type=PROGRAM&Expires=1472208081&Signature=ACvS7HHBSK2yXkVt1z7TrihTAhiYGxWOuYZ51-57Iv9sWySMLBSce5RLuWB1jN7asTFpF0GjlcR5cbbUwtf1~hovGmkbfnSeQPzN0c3CFjUq1-unXh-roYKI78-vNpCgyW67fzL6gj~TV8hAWJSAX9LOUe8Nwnnxu76JdJ6fZbE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Install_PDFR_v224.exe

http://gsf-cf.softonic.com/30a/15f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=40709&instance=softonic_en&type=PROGRAM&Expires=1474422949&Signature=dn~coZQAjgMdu5SCGKdLrFksHo9dFmA9A6iqSuQA5UbZQZA3EUCIpcDdaSz65kvBREnvszc3dZsytou3Gn8vSbMjls1edXa78freQkfixELy2PCmb9HE7FF10LCv4h~jtmEfsz35LURSGCR9elkg5eQZmce8DXCU6jpb8GxvQUc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Install_PDFR_v224.exe

http://gsf-cf.softonic.com/30a/15f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=40709&instance=softonic_en&type=PROGRAM&Expires=1459532007&Signature=KVIQWApyupKcaND9lzaE-fZ7kJ9OrfvpqYo5a8fzFnyWZYtmThBHEjR-mRuAwEMifeWlt74MCeiWSoWyRHy-Tktraew4y8uvluCB1BbwFNnB96OR3TPoDcG7ZI3s7J8iTEykiWJR2kRQjG5LtS5ID47cpPHRqDfdv~p9VI3rKi4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Install_PDFR_v224.exe

http://gsf-cf.softonic.com/30a/15f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=40709&instance=softonic_en&type=PROGRAM&Expires=1470686848&Signature=h03fv9sKo6wxSUO5jaG1DjsjcTzemoh7J3ziYwTXMJIKlYr6AlAWDdLLOuB-Xn9ugvcJbhtC6grt5QykMmG2ojViAuzDRH3ArfPxnnyIxd2SVYDyPhdemRHe-iphDzNqjYLCU2X4LA8hfYeFfEhIP5zstARs8aCmPaDd-peM4Jw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Install_PDFR_v224.exe

http://gsf-cf.softonic.com/30a/15f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=40709&instance=softonic_en&type=PROGRAM&Expires=1480956728&Signature=EjBHNzInx2Qs~xV9F96zxNqDkMc6Cg64emQ7T-JzfcQDPEdkDfJDQQ3ARnMD8Z7hgFwAz7RTzSY~IvhFzycoG2lWf-skkURBggcSInOpULOVHcCGzdx1HwSc7O96KDUU0PsTuMYLQc2ZDSelxjZf20Mk9gingKhnNWX5~gWNMYk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Install_PDFR_v224.exe

http://gsf-cf.softonic.com/30a/15f/.../file?SD_used=0&channel=WEB&fdh=no&id_file=40709&instance=softonic_es&type=PROGRAM&Expires=1476678780&Signature=AH27R3NdxhFD15g9JsMBQ303VaUSNe2bmT2v0p2bgw4HRbWBEJkgDXOCBLtLs4c89NV5jdsrctwxu2LSpAhRxkh2HVPbTXulGod4DzVvPEOLVgv~o3PueE92Bqi6nUL9wL~zWK3B2J3M10-yOLQlIi3wgCBMybvC-gUfaVc0XFY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Install_PDFR_v224.exe

Scan install_pdfr_v224.exe - Powered by Reason Core Security