pdms_fontssetup_b2.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from www.quranexplorer.com.
MD5:
6eaa5a142f14df16394437d54edbf150

SHA-1:
c19e366bf4b76e5ea636c30ddf999a3ac204d8f9

SHA-256:
9d1b8c9f6ef02f31b62ec62eb962560024f516d9db5b452747b683601c55e99b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/4/2025 1:52:06 AM UTC  (today)

File size:
556.8 KB (570,168 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\pdms_fontssetup_b2.exe

File PE Metadata
Compilation timestamp:
6/6/2009 5:41:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:K6HWI9+jGDlymkrPDxThvWmhLJ+6PVZClFwGf0Iv2yq:K6HWbC8DPDl8AmwkD2y

Entry address:
0x30FA

Entry point:
60, 0F, B6, EF, 53, 0F, C0, E8, F7, DF, 89, F0, 0F, B7, ED, 89, F0, D1, F3, 86, D8, F3, FF, CD, E8, 1B, 00, 00, 00, F3, D0, CF, 0F, A5, C9, FF, C0, 86, DC, 09, F5, 81, F2, FC, 3E, 00, 00, 48, 8D, 3D, BD, 20, 3A, 6D, B1, 21, 4A, 81, D0, 24, 67, B5, 5A, 0F, BA, E6, B3, 33, E8, 39, FE, 0F, AC, EF, BD, 59, 0F, B7, FA, 8D, 15, DC, 96, 1B, 58, F3, B8, 58, A5, D7, BC, B0, C1, F7, D7, 0F, AF, F5, 81, C1, 20, 56, 03, 00, 69, DE, 1D, 8D, 01, F7, 81, C1, B3, 03, 00, 00, D2, E0, 89, EA, 0F, BD, D7, F6, D3, 0B, EA, F6...
 
[+]

Entropy:
7.9759  (probably packed)

Code size:
23.5 KB (24,064 bytes)

The file pdms_fontssetup_b2.exe has been seen being distributed by the following URL.

Scan pdms_fontssetup_b2.exe - Powered by Reason Core Security