pdf2word.exe

VeryPDF.com Inc.

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from d110.cdn.m6web.fr and multiple other hosts.
Publisher:
VeryPDF.com Inc.

Description:
VeryPDF PDF2Word v3.1 Setup

MD5:
1049a1e7a461639931b8a8b461244ff0

SHA-1:
5e663667f4b56d4e928b336df55bac037a05c69f

SHA-256:
83542648e367891b31f15f3138828ac00a79be16f0f31975203b7847dc619f8c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 1:58:48 PM UTC  (today)

File size:
5.8 MB (6,095,673 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\pdf2word.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:ediqc5Wpw7FpxHlD3DkiEisaLqTtSgpPeoRmTUVinsaw4hOqCqhRKDYbDybRHrX4:iiqDpw7z73DUislTPxAQssaw4hOqCqfD

Entry address:
0x97F0

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, D6, 98, FF, FF, E8, DD, AA, FF, FF, E8, 00, CD, FF, FF, E8, 47, CD, FF, FF, E8, 3E, F3, FF, FF, E8, A5, F4, FF, FF, 33, C0, 55, 68, 9A, 9E, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 50, 9E, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 5A, FA, FF, FF, 8D, 55, F0, 33, C0, E8, C0, D1, FF, FF, 8B, 55, F0, B8, D4, BD, 40, 00, E8, 87, 99, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D4, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.9993

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file pdf2word.exe has been seen being distributed by the following 37 URLs.

http://d110.cdn.m6web.fr/soft/.../pdf-to-word_3-1_fr_63032.exe

http://soft.vip600.com/modules.php?name=Downloads&d_op=getit&lid=4282

http://www.slunecnice.cz/sw/pdf-to-word/stahnout/.../?m=f05211d774018132449713adb6098435&t=5530ca70

http://pdf2word.de.softonic.com/download-tracker?th=1/.../uPQc3fQg37XnoeQh0ztsUKGT1JHJrbr2jagM2FL3scoU4ylUH02 kjbC5sN8NI1OAb5tOu2VX22MBqfis8LM=

http://soft.mydiv.net/win/dlfile4c7e0_240320/.../pdf2word.exe

http://soft.mydiv.net/win/dlfile4f932_240320/.../pdf2word.exe

http://pdf2word.it.softonic.com/download-tracker?th=1/.../uPQc3fQg37XnoeQh0ztsUKGT1JHJrbr2jagM2FL3scoU4ylUH02 kjbC5sN8NI1OAb5tOu2VX22MBqfis8LM=

https://pdf2word.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/.../dVbUsWkVeRCqlVrAALTHKvHjqRpM a8HCUeIXqxdd98evtEC2G3rJOxmz24JgSfoIQaKRByaI7d3ZcX0S7Y6Qp9x360wMLgzW88T8I1V9chGcC5rA=

http://www.kaldata.com/modules.php?modid=1&action=download&id=949

http://www.capitalheartlaboratory.com/Cqfizk6eVLPI3GEuxBRxLAk3kqAANTbOQYXJcPadBb6ig7efs0doy4bOoH9tdwX3fG2jvPOkGhLUw_mPC3nm3B2oKrRJd_7T3WLUNgw7waWI2oZVjrl9tjhDrgxfDNjzow8xu7ecK6MSql1PnzXo9Nnm1gcckV6PkhaVkTjay7cJY5K V4QX_z0dc_ ew3UTCe8 fTU3FfxjTnGq3OLcodZMtGWdNDqni_5x7TzUth9V1PLEQlJpknix3i36f8VROm2DuCapYb0rKB4BQFP7IiRNhof7nUfTBdla5s1opouRXkhpsMXchluHCV1Xwad0vhIMN1Oxyp8j3W2L4dzGiNVYGfyfDkLWYdboLVgHEXH_LEb8akQPeRA9gxgA9pbA2gS7g2FlM w3bmDQRWrQXRKjtyNszIcHlP1_bOOnMdq9HFrJhAoXoNYBA5eqA1z1oFpOyFJil 2KBLiq Pw0qqL2kVEjkNbPKXhZRk1oIiqDFkoALVxqTAFC g1vrLcz4INK5I24-GyEAAEQnh3YI T8FX9CqCxFllIFkB57UeNhYzYd2K3SdBEIn-e

https://pdf2word.en.softonic.com/download-tracker?th=1/.../uPQc3fQg37XnoeQh0ztsUKGT1JHJrbr2jagM2FL3scoU4ylUH02 kjbC5sN8NI1OAb5tOu2VX22MBqfis8LM=

http://share2.earthlinktele.com/download.aspx?file=1630199266&sig=MjEvMTAvMjAxNiAxMzoxNTowMg==

http://lb.cdn.m6web.fr/d/c/a/bb35c82407341f15dcbb00378af39e87/54fa280d/soft/.../pdf-to-word_3-1_fr_63032.exe

http://www.techtudo.com.br/_/software/.../download

http://www.slunecnice.cz/sw/pdf-to-word/stahnout/.../?m=d6751f97e7747480d05c937d8b444e15&t=52d2940c

http://www.pdfwordconverter.net/.../pdf2word.exe

http://96.126.117.29:6080/php/urlblock.php?vsys=1&cat=15056&title=malware&rulename=outgoing2-7&sip=10.77.22.20&url=http://.../pdf2word.exe

Latest 30 of 37 download URLs

Scan pdf2word.exe - Powered by Reason Core Security