pandosetupnci.exe

Pando

Pando Networks, Inc.

This is a self-extracting archive and installer. The file has been seen being downloaded from www.pando.com.
Publisher:
Pando Networks Inc.  (signed by Pando Networks, Inc.)

Product:
Pando

Description:
Pando Setup

Version:
2.5.1.4

MD5:
8302f0e431594cdc0fc68d6fb6ec7e30

SHA-1:
74681137281dc68215e8a909fd9decea6c8b304b

SHA-256:
a82a7e6a3f732ddf8eb9339ce7affa8f9856f2ac73530354da37699d94706ac9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/7/2024 8:09:23 AM UTC  (today)

File size:
5.4 MB (5,619,872 bytes)

Product version:
2.5.1.4

Copyright:
Copyright (c) Pando Networks 2009

Original file name:
PandoSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\pandosetupnci.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/17/2010 2:00:00 AM

Valid to:
7/1/2011 1:59:59 AM

Subject:
CN="Pando Networks, Inc.", O="Pando Networks, Inc.", L=New York, S=New York, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
2F001A87D65FF9C4708B855F48B0DF1E

File PE Metadata
Compilation timestamp:
1/25/2011 5:31:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
98304:jiVXGC5X3If77Xc9cYkfS3BKqZm76u7vYu59uZQMvxnN9EP3YQaAUmAyQ:j5wIfPXc9cYjB1ufvumMhpQaAfPQ

Entry address:
0x101DF70

Entry point:
60, BE, 15, 50, EC, 00, 8D, BE, EB, BF, 53, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 13, BB, 01, 01, 57, 83, C3, 04, 53, 68, 56, 8F, 55, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
5.4 MB (5,611,520 bytes)

The file pandosetupnci.exe has been seen being distributed by the following URL.

http://www.pando.com/dl/.../PandoSetupNCI.exe

Scan pandosetupnci.exe - Powered by Reason Core Security