lockdownbrowser-200-04.exe

Respondus LockDown Browser setup self-extractor

Respondus, Inc.

This is a setup and installation application. The file has been seen being downloaded from www.respondus7.com.
Publisher:
Respondus, Inc.  (signed and verified)

Product:
Respondus LockDown Browser setup self-extractor

Description:
Self-extractor wrapper for InstallShield setup

Version:
1.0.0.1

MD5:
977b932d8a79fea2241149f00e2e082f

SHA-1:
25e44894af3114a42fd6e14288b7d82fe9c4e200

SHA-256:
fdea1e1af598f74dc407d8fc729e7c159a692e08625fe54b39ea576ac5a6fd71

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:31:49 PM UTC  (today)

File size:
54.2 MB (56,829,488 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2015

Original file name:
LdbSelfExtractor.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\lockdownbrowser-200-04.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/20/2014 5:00:00 PM

Valid to:
8/12/2016 4:59:59 PM

Subject:
CN="Respondus, Inc.", OU=SECURE APPLICATION DEVELOPMENT, O="Respondus, Inc.", L=Redmond, S=Washington, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5DFAA2E6E50A68F6FFE2A69C8E6E8CE7

File PE Metadata
Compilation timestamp:
3/27/2015 10:34:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
786432:/oJEqTUsQ5qDG/E+CLcuON/Bu0BiLqXz0s3w7KaOx94cHv6paI/tDMsWn2S4j8Az:/2EGhG/EXLcuIBuIB79PipRxMqRx

Entry address:
0x783A

Entry point:
E8, AF, 4C, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 68, EC, 41, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 50, D5, 41, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 68, EC, 41, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00...
 
[+]

Entropy:
7.9989  (probably packed)

Code size:
77.5 KB (79,360 bytes)

The file lockdownbrowser-200-04.exe has been seen being distributed by the following URL.

Scan lockdownbrowser-200-04.exe - Powered by Reason Core Security