mstdefrag30he.exe

mst SelfExtractor

mst software GmbH

This is a setup program which is used to install the application. The file has been seen being downloaded from gsf-cf.softonic.com.
Publisher:
mst, Germany.  (signed by mst software GmbH)

Product:
mst SelfExtractor

Description:
This file was packed with mst SelfExtractor

Version:
2.0.0.0

MD5:
171ee2ac1022e2f0a46603f52eb496c6

SHA-1:
0520100877498ca397e1f969d8cfe87de9329ea3

SHA-256:
284366d36fee9a9c7f3e5b56452c35b565de4844440926d44f5b9928550211d6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/8/2024 6:51:42 AM UTC  (today)

File size:
3 MB (3,153,408 bytes)

Product version:
2.0.0.0

Copyright:
mst. All rights reserved.

Original file name:
SE.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\mstdefrag30he.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/16/2008 3:45:08 AM

Valid to:
6/16/2009 3:45:08 AM

Subject:
E=info@mstsoftware.com, CN=mst software GmbH, O=mst software GmbH, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000011A9055B955

File PE Metadata
Compilation timestamp:
6/18/2008 3:15:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:3vd8+DlA6zliwDTsUkrrH14i6Mo9fdDPpvf:3vd8yzYwcUQrH14i6MYBH

Entry address:
0x10C5D

Entry point:
E8, 82, 73, 00, 00, E9, 78, FE, FF, FF, 3B, 0D, 78, BD, 42, 00, 75, 02, F3, C3, E9, 04, 74, 00, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 78, BD, 42, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 78, BD, 42, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00...
 
[+]

Code size:
135.5 KB (138,752 bytes)

The file mstdefrag30he.exe has been seen being distributed by the following URL.

http://gsf-cf.softonic.com/052/010/.../file?SD_used=0&channel=WEB&fdh=no&id_file=59373&instance=softonic_es&type=PROGRAM&Expires=1456723335&Signature=HBkiKAbLmbUOieLdOfOn04pXrQW0ohPuC0ur3qkjtpP~XNEq9eSGooO~yCQL7p-u8ZoyAqtRpMkgMNMQkUro8vJbKni70RpE28~ReB84n1DlNR63FMCE7BkXud8mAEzPplmr3RiPsAbp6pj9nGnckZVraFujNGH~xFKJrvu-nW4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=mstDefrag30He.exe

Scan mstdefrag30he.exe - Powered by Reason Core Security