pdf-unlock-tool.exe

Estelar PDF Unlock Tool

Estelar Software Inc.

The executable pdf-unlock-tool.exe, “Estelar PDF Unlock Tool Setup ” has been detected as malware by 9 anti-virus scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Estelar Software Inc.

Product:
Estelar PDF Unlock Tool

Description:
Estelar PDF Unlock Tool Setup

Version:
1.0.0.0

MD5:
9fe1535abe65091a5f6cae2f5e00cce7

SHA-1:
1eb0cd13455c240a8d8518736980e19bce13eec6

SHA-256:
93a20ba2ffcdc1afacaa27b4b11f3adfb68e75e00a9438204b4575827e670363

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
5/7/2024 5:45:24 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Backdoor.Generic.945899
706

Bitdefender
Backdoor.Generic.945899
1.0.20.300

Emsisoft Anti-Malware
Backdoor.Generic.945899
8.15.03.01.01

F-Secure
Backdoor.Generic.945899
11.2015-01-03_1

G Data
Backdoor.Generic.945899
15.3.25

IKARUS anti.virus
Backdoor.SuspectCRC
t3scan.1.8.6.0

McAfee
Artemis!9FE1535ABE65
5600.6840

MicroWorld eScan
Backdoor.Generic.945899
16.0.0.180

nProtect
Backdoor.Generic.945899
15.02.26.01

File size:
2.9 MB (3,034,526 bytes)

Product version:
4.2

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pdf-unlock-tool.exe

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:EasjEb9vLrGE7naeIFeXDwRf26wBYogv9ou7RSV264a+hmCBwOxqylluivAc3lly:p68DFnaqDwRf26wSo06u7RSVRsmCBfxa

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Entropy:
7.9791

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file pdf-unlock-tool.exe has been seen being distributed by the following 46 URLs.

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1433511439&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=VraN6X4b-s8c7vol2na~VjW4eSAmCvJJnAjPWKP2G~RjbSeoLN8Fc-TzN5RJdYRoxuVmbke8C~0KCLLLSXbLVAArxSBPy4WB1TJsFjFLkoQR33QA7-uX553x3G9xxb016h--QUjPGuPY37rgsc-W5MepC6PVMMVvRE5B1RIPdTU_&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1445584247&Signature=PfLH0D5k5wmxbFEsey7t8rSLg8B6q1oOowYPzjQ6F7gIfUrWodo8c2nHUC~~ztzUYvH2ChCsvPmoZSzan7tn2~BRF5e~7yaBElbwePkBHCZmpPivnYiXI4wT9V9muV6u0q2pudJ~WqbU1xtlpu-njfgFjOLbZV6r5X~mz4UqYMI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1463921143&Signature=IDT-HctxceIPUHCVoAQF0hOzasEtwPkfBZTtIaBjLi0sb4YsCCUESmkZQWnGUDaVhBhRF0ZLHdAsqyBEXstPBwdmAPJv1FKxl68xvbOqjlQr26NolziHxX81UK5NUMem~5NZGZ1IeuP4P4C-kuannvpipZNPwohUUZ9DyWLwD9I_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_br&type=PROGRAM&Expires=1445038863&Signature=IEyhe67kA-lMREhw8M6WAZ7lJY00UUDU0aem1VOAdYY5vPG4jT-uQ4sfPeEook1ouWx9cym5t~VlDkVIKQyP7RS904-ciN55jeqXWElKZjGtVytN3wZu4r0vTsQ9gQnJIHBTVwHYaNBE~gVAGna2q9Iw1TR5Gf2HbmhBaBemN4A_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1481636505&Signature=heJimhSybDT3c0bJdWEBm6Gk6HxgIbc-K~nzFL-5RMw7-uS-Q~c9kFuH6agnkG9QBMD6KsszO7nKqAX50H51kgPyyIIL~7Ng5Rs8qshyOTnDQAopfqOlQ75CbjTXF5AeF5lquIbAmSb-3ajeZe~fb6LMWnpnqIP~YuWbqla3vzA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1466330022&Signature=S40jE8QxGSERLCpZN-YtidZz3YRnOYpCCseuF1JoQjqZA22Oke7GtsRJpXVT6SiWVjuqF30qWmZDpxsSlaBm0qKDUZYo6HhWAofSOECp~mlpHPN9Qz5kX5Qc32Q0CtJcD7Z~vxUN65yD2PNT4MBuU5hGMLmV7L8r6jIIPXQR5uc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1439970981&Signature=G5feeBwN-vYrmsNgzO~AEx3DGMGf-Bun0-x72NiZq-g0GKFJWSiUrlZljUc5QM40C3IbmdTNN-508Z1SRhaFAGVQL9TUmQAyahKaI3HL-QJQTbA0~thMcEvbBGv652Xe3i5bxjYkzC1RsTIarxBZuA1x2C5Hpo0hYfe-vEQYwkA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1472001647&Signature=efYO2mg3G12lHbE0fXE4c6W~ltf-tFw2Otw5ucjTbAIIuit379u7-HNbz30nBxDqSuVGHpeNN6PH0-R43TX7DUxrytpliA2oMn~weBNggoTguQO0~RUUD8F7CX8-9WXjVXHOMgvKotBdEUFD2GVJOahlUKAXcA177Peuu16uxOE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1434255292&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=F7WpQgl4wuwA6ChIzQtYRihv8UxXiZDM8ilHUuJOvYYQC-YcMMUXUZooJhlbXH4EcwEnTeGliaUmWCfWBKcmvZNTSgQqGMqrjSakv5NauzWtgpIG5XHzr83TCIuYaa~ffC2uhpzPJq~u0J-smBD7cd31uSg2GfC6cqeGd-apCu8_&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1448336083&Signature=DjRbY59eb5zhUYLis2YTduB6qsmOocYrcszTx7UxkaBoqcbD403iHZXvjthGzbKz-5GKKhhO0ummLdIxMwJzMDycQetlIRxWI3AfpPgTXv-FnBx~EaDUDxlYmhH5x4I~UFk3sDKHT4T9OlVEp~2b~v0vxvrs8iyyJlfw3VtIpuc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1476134120&Signature=F50kexGQleCHyrnBn27kZMU1v-y5mb0K1oChrqt0VBZDaRhBq8ZMSB-lcxQs0WseetjH2xNvHQtsVfPFDmGaIVKUsGZBSwtjejcuvJyE3DMyCdzZ39AawOyMk540HDWWCXlQHDYW-OAeXj3Y0nGVCA~ypA3cX3JE6fYdyAmUrIE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1473121779&Signature=WvUD0xfI-BblzIh4w20E0i~9~bCy891iXjqkotOBlUcdD5oitFfig8W~Carc5wp6PapBnTpdRvHSUPD3VKRR222CNbxoXtFlojZ~q0OVV6fWQCAn42STXwlTpsDTdTfGKNmy1qNxd3TxQ-eCgQbCkVMpzpA7UulOh5fUK~VBIpQ_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1474981532&Signature=hU97o1tvUzvF2~PFnxqKD88~MhbuBa2iKNSfoZfdac8ZbWlUetAqPw-8IdPgAgGUWx-a98QhwV03YvnRRe7GKPTzJznOOqdPHvUtgyvWuiPdM~tX9kHrCUb78YfMIiivMJGnui7zR5cHu2Zofs2oDipn7i8smzJA3igC5WhlODk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

http://gsf-cf.softonic.com/1eb/0cd/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3338333&instance=softonic_es&type=PROGRAM&Expires=1443575130&Signature=D3twyO93dticbb1W8ynt-kd9ycHFMwbXDIgZw~6pyv4Yo1-Mj8pvr9vhmDcWmsUxtmUtY2Mr3dE1guFE8Y6ZoyyNXpVuWcoUgSOamRDpXPg2Q8xSWZ~Ltq6MTTqbvCLuVTOdKoBijHnqHoNs8PUwK4agI9QiOu-P7qYL4~WBNAI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Estelar_PDF_Unlock_Tool_86636.exe";filename*

Latest 30 of 46 download URLs

Remove pdf-unlock-tool.exe - Powered by Reason Core Security