kte_16_691525.exe

Shortcuts

digital publishing AG

This is a setup program which is used to install the application. The file has been seen being downloaded from arazoniabarcelona.com.
Publisher:
digital publishing AG  (signed and verified)

Product:
Shortcuts

Version:
12.0.0.487

MD5:
230bae3f2c6005e10ece62836612b448

SHA-1:
72e0e02a8fdea8d2928491eac59dbede2a0d4c00

SHA-256:
a042186b17f9e28ba67cca3e6a834cbb320a77bd3e5c6b2772aad5a0d2136a60

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 12:49:00 AM UTC  (today)

File size:
332.8 MB (348,943,192 bytes)

Product version:
12.0.0.0

Original file name:
shortcuts.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\kte_16_691525.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/11/2013 6:00:00 PM

Valid to:
4/13/2015 6:59:59 PM

Subject:
CN=digital publishing AG, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=digital publishing AG, L=Munich, S=Bavaria, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
38DD41B6961DB893256FCCB4A36CDB5B

File PE Metadata
Compilation timestamp:
8/8/2011 10:08:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6291456:iWmAdYLgPKEFpJ5+keTtxqaRhWYZMdhOmGBJre2SIodaxzcINdg1SMqZyV:vmlLgBTJ5UpxqaWYUFGBJre2SxaxdasO

Entry address:
0x29D12C

Entry point:
55, 8B, EC, 83, C4, F0, B8, C4, 94, 69, 00, E8, 34, AB, D6, FF, A1, 0C, 6E, 6C, 00, C6, 00, 01, A1, 80, 73, 6C, 00, 8B, 00, E8, A8, 10, DE, FF, A1, 64, 72, 6C, 00, C6, 00, 01, A1, 80, 73, 6C, 00, 8B, 00, BA, B4, D1, 69, 00, E8, 5F, 0B, DE, FF, 8B, 0D, E0, 73, 6C, 00, A1, 80, 73, 6C, 00, 8B, 00, 8B, 15, 28, FA, 63, 00, E8, 8F, 10, DE, FF, 8B, 0D, 28, 72, 6C, 00, A1, 80, 73, 6C, 00, 8B, 00, 8B, 15, BC, D6, 67, 00, E8, 77, 10, DE, FF, A1, 80, 73, 6C, 00, 8B, 00, E8, A3, 11, DE, FF, E8, FE, 7E, D6, FF, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.6 MB (2,736,640 bytes)

The file kte_16_691525.exe has been seen being distributed by the following URL.

http://arazoniabarcelona.com/.../KTE_16_691525.exe

Scan kte_16_691525.exe - Powered by Reason Core Security