pb204.exe

PictBear Second Edition

Fenrir Inc.

This is a self-extracting archive and installer. The file has been seen being downloaded from ftp.vector.co.jp and multiple other hosts.
Publisher:
Fenrir Inc.  (signed and verified)

Product:
PictBear Second Edition

Description:
PictBear Second Edition Setup

Version:
1, 0, 0, 0

MD5:
fd8dd752f63635769df19071dd4261a6

SHA-1:
caa041d55ab6e3405ee0fcfbc936e3985eda9735

SHA-256:
9a5c8ffd2726fbf679cae69ff018dda8766db1b930e7414d72180180e11dab5f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 7:41:20 AM UTC  (today)

File size:
3.4 MB (3,610,464 bytes)

Product version:
1, 0, 0, 0

Copyright:
Copyright (C) 2005-2012 Fenrir Inc.

Original file name:
PictBearSetup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\pb204.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/12/2012 9:00:00 AM

Valid to:
1/12/2013 8:59:59 AM

Subject:
CN=Fenrir Inc., OU=Fenrir Developer Team, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Fenrir Inc., L=Osaka City, S=Osaka, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
18A835D6795A29FA0DEFC39DD1836C47

File PE Metadata
Compilation timestamp:
2/21/2012 10:58:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
98304:8z0eSckSa+aNmynIA6VMaJ96Rb7OYzsqUq3oP9:Gk5awI16RnOY7F3o1

Entry address:
0x2957

Entry point:
6A, 60, 68, 40, 86, 40, 00, E8, F9, 03, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 81, FF, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 48, 80, 40, 00, 8B, 4E, 10, 89, 0D, 38, A3, 40, 00, 8B, 46, 04, A3, 44, A3, 40, 00, 8B, 56, 08, 89, 15, 48, A3, 40, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 3C, A3, 40, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 3C, A3, 40, 00, C1, E0, 08, 03, C2, A3, 40, A3, 40, 00, 33, F6, 56, 8B, 3D, C4, 80, 40, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
7.9791

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
28 KB (28,672 bytes)

The file pb204.exe has been seen being distributed by the following 14 URLs.

http://ftp.vector.co.jp/57/17/.../pb204.exe

http://download.forest.impress.co.jp/pub/library/p/pictbear/.../pb204.exe

http://gsf-cf.softonic.com/caa/041/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3350474&instance=softonic_en&type=PROGRAM&Expires=1478062870&Signature=WL26KFbEgvNrkDzBwmN8vWgzLHdf-mS06dVQ6qECYnRuMlEfpYCvmbZE4I8Q601QUA25YMbbMD7mvfTb07ghOWL0alYA5qx0rqM10Hq-QPkmhRCB0M7Dj84B293nYJtD3rt7DaEdo8fRCJr6lyNs-l~tmZxfAQJrwX1QEfEJV~4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pb204.exe

http://gsf-cf.softonic.com/caa/041/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3350474&instance=softonic_en&type=PROGRAM&Expires=1482130755&Signature=JO54~KFlLes78maqZaml7y6hQZNFKjaQ2Y~LSzd7Ir4m19IaaNXysN071oD-GHc1kN4KO3lWKMKJdBXESBCA0IJ8ZNctMGt9nxL5yr9AM97acgLR6j7fQAFrRBvj5uMjBkJ9U4~bT06KIARh4XzBtg1ZuEAxHmev05VMBJg8xy0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pb204.exe

http://gsf-cf.softonic.com/caa/041/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3350474&instance=softonic_en&type=PROGRAM&Expires=1474020551&Signature=VerSZyEGHpy3ACeTNXU-nho56xcahpFcUS5g2VtLiYrpL7cZGXLiiqoSvLQGlzoP~vv6MzcRmnpucgFb4gDGQAFP8a3~3akdgeJQgmyhh1lQowabP6J4LiIYS4md5gwtGBBEBbZYKTEJyWa~nzp3LSPbCS2YE2xwNK2zahwaf6A_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pb204.exe

http://gsf-cf.softonic.com/caa/041/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3350474&instance=softonic_en&type=PROGRAM&Expires=1475141841&Signature=d270QZ3LWKIAnoQ-~Tl69nGsFxtP7cgtQdDpGh0PagBURjqVMsRJOfJmYavFQMJiBwicUejNJmbq5DnBywzALozr~2HJGmZFFyoFnHpCB26sjKs3XrNy1DGzaaqvucQmJer4QlvkymkQVuwtW9CZmZbx0~A5nYmGP2O0rLm~7-k_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pb204.exe

http://gsf-cf.softonic.com/caa/041/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3350474&instance=softonic_it&type=PROGRAM&Expires=1479287582&Signature=iEFtHkrHx0kYcuwsmZRK6XBNxrs2X31C0-L6MobX517DnLEOvLEZBeIP3iETDGmNctvcduoaZmswxW~ZsaRYhWhHY2zzmK9DOukorqCrwJfvjBRR-uXxuJGXHzHhbXSPvbDeHcGsOZbBz9O0i3bhJEGoGF2I-po-1lObLxvHTFk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pb204.exe

http://gsf-cf.softonic.com/caa/041/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3350474&instance=softonic_en&type=PROGRAM&Expires=1479210431&Signature=F9p45gr4fEpM6wm-0CA7x4WhWXofiatzSMW2o~YaE2q-GaNXWmPaDliVIzVhxLilXpdEBNrQg48CfimvR2xR1-LDi5HbNkpbHkb08galT0WrNnLKLjoJl82deROIxsk2UPLJ~fuKOlWrokR22~-Z2FpIWE56S7yJm~tznNIDYhc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pb204.exe

http://gsf-cf.softonic.com/caa/041/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3350474&instance=softonic_en&type=PROGRAM&Expires=1467672697&Signature=RE2YrecvoNUbcfCVrubu9KKoHZp8uVJpFf9fVRNtsmQc4t3FpwIQmpDgngoa6qmVbwTgFbMbQRe42DuQwEw3UnLQVzci55~hMAmVBLXmPEJRxlgI-2K5U4X3S0gp0QihFCTuwE3XmwMrllqrhuD2JOpZQGB-3LPWUZFFCN5lCAc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pb204.exe

Scan pb204.exe - Powered by Reason Core Security