pdfcombine.exe

PDF Combine

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
PDF Combine

Product:
PDF Combine

Description:
PDF Combine Setup

MD5:
7faf2c445550dbab2c62ece62dee2431

SHA-1:
0a074c7b49cf723d727b569b9b93239e8765e76d

SHA-256:
135588cd4b55436d64a1f272988716780a027294546e294aa207809529e44ba8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
8/6/2025 11:38:22 AM UTC  (today)

File size:
2.8 MB (2,923,523 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pdfcombine.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:32KJE0Cp5BLS4pxmc0qEw94vGt+sBzDo2D/EQXXcofYOQtoqXr:msO5I4Ka98sxKqur

Entry address:
0x9B60

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 66, 95, FF, FF, E8, 6D, A7, FF, FF, E8, 98, C9, FF, FF, E8, DF, C9, FF, FF, E8, 0E, F3, FF, FF, E8, 75, F4, FF, FF, 33, C0, 55, 68, 17, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, E0, A1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 02, FA, FF, FF, 8D, 55, F0, 33, C0, E8, C8, CF, FF, FF, 8B, 55, F0, B8, F0, CD, 40, 00, E8, 17, 96, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, F0, CD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.9571

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file pdfcombine.exe has been seen being distributed by the following 25 URLs.

http://gsf-cf.softonic.com/0a0/74c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3349393&instance=softonic_en&type=PROGRAM&Expires=1475690903&Signature=ZIGzTxVwCE39mXSomidFl3iTJWbcf758h7wWoXmGmMAL-qunsp3FfKmXeBAgZljqKPQlwd8qci~Gf0tcDHuG~pNAzug-Ga8KMkt9wsQYpEGiZQpGqpgixKH0PZDAZBWxqHNWgo~RDPhRhngklbJvwNvFeLstufHQwgVWQ8bzW3s_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pdfcombine.exe

http://gsf-cf.softonic.com/0a0/74c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3349393&instance=softonic_en&type=PROGRAM&Expires=1475413690&Signature=Sw2GHx8J-5eL0pMCihYpfKRNEcL0Uo61aLI9JUFS50EiPqZq0tljBDPivmRzhBT0A2qwrEGZi2fSh-MtWpFDbP~geZPM4vEqUd2FmrQItbxsiDsy0ZBjK~tNTUFWIqKgKHnxODU1oBjY60OHBU6TL41tWxhv3m32z5hQD25ZRgE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pdfcombine.exe

http://gsf-cf.softonic.com/0a0/74c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3349393&instance=softonic_en&type=PROGRAM&Expires=1434956399&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=P4YPvUQALorXCZbC9vWDOScFRA0Eb6sGQ~rAdHsj0wAX1YR-Ws3rvVtrUIST4yht0ECil3Bf~llrvkz3-ILbfx8DKF81ZLVlk6gmUxiI5mkaqrSbAKlMBaRFDRdlNCbKPnhtlT9100spP3f--BO7CY9Jcy1AtTaOxI6kyVI~8DU_&filename=pdfcombine.exe

http://gsf-cf.softonic.com/0a0/74c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3349393&instance=softonic_en&type=PROGRAM&Expires=1439468895&Signature=VMeN-TJ-FClIC5p~1MsNoK0dbOdSh6i6cQyvojQexVZAOl0U9FJUN3gd5AqqVkMdYNRU2OKigNmq-Eq3XKxGzp198ZWAZUUZ-USLhbnAGL3C5m6-Y7ul17r3f~CS~etU0qqWM5U0Npg8CQWTp8CDBng6MLb7KHoe0ZspnXnQ48Y_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pdfcombine.exe

http://gsf-cf.softonic.com/0a0/74c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3349393&instance=softonic_en&type=PROGRAM&Expires=1445266303&Signature=LO-313VFDqIcEGVxwavNT~C18p1xX3FYnYY9l0uH4vFSM7I6V69z7UAtfINeBQFZE89nzhZmOuS6nTtl72Ky9QqJHBh8A3zV4dz4IiwJH8bhX2kVTmQIUjUkVPYun5vCrgKAk~GanPqZj7BfXMH5w-CM-ihCIz~pWW1Sb5tZJg8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pdfcombine.exe

http://gsf-cf.softonic.com/0a0/74c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3349393&instance=softonic_en&type=PROGRAM&Expires=1465320938&Signature=HCCXK-nWcVEhsv9~UX0ItsOxE8-vccUXoRslMzLNTIY6ZOmScL8PhhHcrqtkuen3jt7OMCUlt6y3kLbE0bbK1JpGoRBwcs0xcWNbYgy4353e4O4bygJ7Q9oGVnpO8elPUAmStc08dEWb2yoJd3bYzH4A9t~B55I-KUhYHsGCmj4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pdfcombine.exe

http://gsf-cf.softonic.com/0a0/74c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3349393&instance=softonic_en&type=PROGRAM&Expires=1477617589&Signature=Ky5Kl9cybF7YkqjGorF3HGN1jAqhhSvibRwrHrSCZMsLzHTs0F60YoUk6kuVxcvjROQz~z6-OBcQMssHJzlUJmgP10znUb8t6-6yPSqE5RlAzbtnwcLOgJf9uzNdHroLOuYDducZUtvG0qKzb2PAOFVfJl~qEsLWWhm5n6iXIqY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pdfcombine.exe

http://gsf-cf.softonic.com/0a0/74c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3349393&instance=softonic_en&type=PROGRAM&Expires=1441673619&Signature=R~2D8IrQkNDpMQUu1JutSqFjN2Fr-zkrSzis-v4gla6vg-e4pEoTFuM76KfPnQlBSXI-7IinuldDRHLa8PD9DohRJED~7jWqE3vpjadiZbivhaC51FHnQ157E9Wj1T30L44cTkXiTc3igcpLPsnMVbIkhYTuhIp-2uGQWZVqtD4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pdfcombine.exe

http://gsf-cf.softonic.com/0a0/74c/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3349393&instance=softonic_en&type=PROGRAM&Expires=1446238758&Signature=DlLjWkOtT6EKiA47m3lHysgZiKMDbz4QLGVf7S7m0zW3xun0~43yQzTnjPwtjPeTISgjnnSnSfD5ZFXQxeLgrv8dvhw72Eori2ojKd~eZ7TSNSsdnnXvS1DryxFcbURMkUR6rM1~Zgd7hRcUajWx-wlIjf1UNGDz3nuXst~5dXo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pdfcombine.exe

Scan pdfcombine.exe - Powered by Reason Core Security