pixelruler.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
MD5:
29a9ed9d738170f2492864f4ece7d0cf

SHA-1:
5b1b3d40e6fd7fd59f2027af2c0494fda9d085d7

SHA-256:
78d408840c1e1eb092c5cf17437dc826ffa6a90c2938047f0a6b78027e358cce

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 11:43:01 PM UTC  (a few moments ago)

File size:
732.6 KB (750,197 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\pixelruler.exe

File PE Metadata
Compilation timestamp:
10/27/2004 7:34:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
12288:V3PSp80VCBk+SVMg+rRGJye2DdKrcqj/FbAO0vRpJmW5IPUZnwFlJXp7Hd:VPSp80Vuk+SGrRXpKx/Z/0J3F5lwFzZJ

Entry address:
0x1000

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, 4C, B1, 40, 00, A1, 3F, B1, 40, 00, C1, E0, 02, A3, 43, B1, 40, 00, 52, 6A, 00, E8, 41, 92, 00, 00, 8B, D0, E8, 4E, 17, 00, 00, 5A, E8, 50, 0A, 00, 00, E8, 47, 17, 00, 00, 6A, 00, E8, EC, 23, 00, 00, 59, 68, E8, B0, 40, 00, 6A, 00, E8, 1B, 92, 00, 00, A3, 47, B1, 40, 00, 6A, 00, E9, C7, 70, 00, 00, E9, 1A, 24, 00, 00, 33, C0, A0, 31, B1, 40, 00, C3, A1, 47, B1, 40, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, A4, 00, 00, 00, 0B, C9...
 
[+]

Entropy:
7.8402  (probably packed)

Code size:
40 KB (40,960 bytes)

The file pixelruler.exe has been discovered within the following program.

PIXELRULER  by Mioplanet
www.mioplanet.com
About 4% of users remove it
 
Powered by Should I Remove It?

The file pixelruler.exe has been seen being distributed by the following 15 URLs.

http://gsf-cf.softonic.com/5b1/b3d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=37814&instance=softonic_en&type=PROGRAM&Expires=1485212044&Signature=cLkVUGAfhLtpj0VupfhexnZ9DRS9Nx5~CbERIcsCraEIXCvb61ZKjFjZM3hDaz9OHB17X~F04XV4VUzddI5CPMMt3Rksv5CWVsWxK-LkB~eI-rgcgSHcfz1Oa7Mej78RLt4zUCDDHlA9a8griaAWrdFdF1FK2kteRfyz5ay~E5c_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pixelruler.exe

http://gsf-cf.softonic.com/5b1/b3d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=37814&instance=softonic_en&type=PROGRAM&Expires=1479879263&Signature=RxlrzgNmyuJoKqDFlF3oHaHt0PFv3K5s0C9BIRrsR1Sx6YB1N42-b393h3gSOyYUof3p3Vlqhj3JxWyzHhHunkwZvvoqg6uWW~D-RSIyOZS99D0JI1YTALfmNF8CfxRBUrwVtIVOCZis-GC089MMva2dhjDgcrWutiXtlmwoyVU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pixelruler.exe

http://gsf-cf.softonic.com/5b1/b3d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=37814&instance=softonic_en&type=PROGRAM&Expires=1442948118&Signature=a5D2TbQz2DuH43LGNwvpEjY0XXkSFyzEDm~HGmosnSRVTTCCwp6hJ4j-xvrq1nOICjZEjKvUrsc1d77vf8GdX~6NSFVgx1BXcQWFq540KajsStPanuce3IG~mPdzJw0Z~J0X6e38Kay1f1IA-qFBSUtCdsB8LnsuiC8Xwfz7pfM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pixelruler.exe

http://gsf-cf.softonic.com/5b1/b3d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=37814&instance=softonic_en&type=PROGRAM&Expires=1476319364&Signature=NenxWSe0vFmGzehCd~qutn3rCv6hBPhq58TLKkqsBxmw9INle42l8FHq2m8pWQsHQlUClUOPlgOHTanbLIlZrMqkfrbkT-wqYPSjdwmem14QAWLjMgPErjivKvDPAR4FSOy0BaBYOk4nWmeErHu6qeTVjZVWIxflLRDvOm4Tkgk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pixelruler.exe

http://gsf-cf.softonic.com/5b1/b3d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=37814&instance=softonic_en&type=PROGRAM&Expires=1436207808&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=iOVyLUh9QUf4Ua2byDgvprMgebYdWJRmJzJBlFbKSy1PVpVxSnrJSHVaSJPJGqZ4sI1HlP4guckfcyRKjKR27KlWLFr4R8ZedksmH61QVXo18BHUbu5VBKZp3jJfmMQuYYmipWnq1EINrE9H9Wv3uDwQljku7~suDFwbA4apWOY_&filename=pixelruler.exe

http://gsf-cf.softonic.com/5b1/b3d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=37814&instance=softonic_en&type=PROGRAM&Expires=1431102670&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=FjUhAkCC1rNmNedRvVjCeykigZBavmH0D05S0WkEMmCnSmaBI6WFWS2VhbYZQv6M7TgAuzT5W3mFPnLRkqb3nsdfNamgg4EibHjhnTQJ6EB6WaCSWXn4vPA5cnrljG66DemuJw5wRhDKVrWHkG0Io9cUEOZRoGE1lz~AJRiLjIA_&filename=pixelruler.exe

Scan pixelruler.exe - Powered by Reason Core Security