poiloaderforwindows_272.exe

7-Zip

Garmin International, Inc.

This is a setup and installation application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Igor Pavlov  (signed by Garmin International, Inc.)

Product:
7-Zip

Description:
7z Setup SFX

Version:
4.65

MD5:
b6f52c14a52b87efcaa1e2e41d125d6a

SHA-1:
81111a960b6484b65d3bd16cbd1678c80b8429f5

SHA-256:
c84adebadad7c9db3007b5378ed51d3ee245bffcd80fbec13a4d8250a465041c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:20:26 PM UTC  (a few moments ago)

File size:
12.3 MB (12,915,584 bytes)

Product version:
4.65

Copyright:
Copyright (c) 1999-2009 Igor Pavlov

Original file name:
7zS.sfx.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\poiloaderforwindows_272.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/6/2012 2:00:00 AM

Valid to:
9/14/2015 1:59:59 AM

Subject:
CN="Garmin International, Inc.", OU=Garmin International, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Garmin International, Inc.", L=Olathe, S=Kansas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
073010462A96B270563264A44F349C6B

File PE Metadata
Compilation timestamp:
7/13/2009 9:10:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
393216:f35R726IWTHRWKyvqnIQH1UMWSLk8BRl3NWIRD:xR72m7RWZDU48B/3Nx

Entry address:
0x11727

Entry point:
E8, 9A, 02, 00, 00, E9, 35, FD, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 38, C2, 41, 00, 89, 0D, 34, C2, 41, 00, 89, 15, 30, C2, 41, 00, 89, 1D, 2C, C2, 41, 00, 89, 35, 28, C2, 41, 00, 89, 3D, 24, C2, 41, 00, 66, 8C, 15, 50, C2, 41, 00, 66, 8C, 0D, 44, C2, 41, 00, 66, 8C, 1D, 20, C2, 41, 00, 66, 8C, 05, 1C, C2, 41, 00, 66, 8C, 25, 18, C2, 41, 00, 66, 8C, 2D, 14, C2, 41, 00, 9C, 8F, 05, 48, C2, 41, 00, 8B, 45, 00, A3, 3C, C2, 41, 00, 8B, 45, 04, A3, 40, C2, 41, 00, 8D, 45, 08, A3, 4C, C2, 41, 00, 8B...
 
[+]

Code size:
75 KB (76,800 bytes)

The file poiloaderforwindows_272.exe has been seen being distributed by the following 31 URLs.

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_es&type=PROGRAM&Expires=1452812691&Signature=dc3eruY4QEL2omAfkqOsFD519hrqeLC8KP1RACQ2y6I9LEDfzkp3hax-VAWlHlzizhaRKYDbpqHhhC83IFxRcfrFIEMMuRJtoP8B9oJTDa-jM0vdnahiaadLlTuY5Lw2XTjzb-Cp9xsfYFQjnUwSDqsAB8VYfNERzIwbvC6DD4w_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=POILoaderforWindows_272.exe

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_es&type=PROGRAM&Expires=1447674047&Signature=b5O4hDbeTJ8KIUY4clc7pi-zaBUyoKZ35Ejou-Lkw1Fo1ac~1DD0Z1Wf-koVXWe-ZcPSZiuThhzK-gsUxno~isJUndo8H4rQI7OXa2cFbJjIfjKkpC~WPlNo8UMz6WC71-wM6LeYGAA4~E1fP4mtOXB9PWHapfYETKx0NDspDWk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=POILoaderforWindows_272.exe

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_es&type=PROGRAM&Expires=1473593743&Signature=eaLYhH3gm85~~szCjswG~MxtwK7eE9FuHhFBfDkqjDTM4erotg~lD5gAnzMbJJy3NVpkmmmN4d4EPVxpJua4nCbi-D3Hh9lXhKcrOSv-592i50rkFUI5jPguQmrnBrXJvvhQuFtv4H3fFcArLQQ9kJD1Z9ut7YNzKH479Us7gCw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=POILoaderforWindows_272.exe

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_es&type=PROGRAM&Expires=1473558991&Signature=M3LLECu5Thhr9x9Nzxa6nlPwg8zlxaj773BScHHLSnMD1FLHJubdYlTI5VdgfHzP7cMs6QOv3O0StG5TA1neVQYudhhz6kxdbJwtxdFxbwKuH-nlzpH1nBVBSml4v6dHuqGXwg5c5Gne9fzK8dA5SCga6lYWLoySJus3ycBgfSg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=POILoaderforWindows_272.exe

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_es&type=PROGRAM&Expires=1428462615&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=hJJ7ct1R7iKjxeAt7SFLb67aiY37CiBaH11M7ZTMTp3IcVV2bZq~pjzhWnbyLMRypQH8dgE3KHnTNSmAjUbry4nCtYlneQoS7Vu9nsM-RWCF0CozaYQFR973T0itKvWR~UGaWBF-ucnOLpES~X3rsy8KHDFn83ZiNV66vh6XVQo_&filename=POILoaderforWindows_272.exe

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_es&type=PROGRAM&Expires=1445562894&Signature=JMoM9C8pj4whyEpcTD9xsPhTEk3og2DtPI6TCfohDwdJ~MJGH~8BxlsgZHoppOwBaBmdwULpt9T87QiVGw5E20Mnr424XJL5YXRc57no3Jg11LtyLrqPBRCEgdMFLOGxYBYet-pXgYt2lm~afDO1aRxfSOu-uDWmqgZcFcckyQc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=POILoaderforWindows_272.exe

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_es&type=PROGRAM&Expires=1459254059&Signature=KcM0oOy5fERxcf79BgkkrHF2SAGqQVDgjTjr4i6coDkhaJOX2cU1c4oeFJj9izTK37AIubG3rjlKji17flSEV7~U74CuitQ7EHKt3SL250~Zi~RyuzNvVbm6~EBfeDULACdFa0lGCSsvf~eV9YJjFg8HcUwtskDvXlQDeAxmSkw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=POILoaderforWindows_272.exe

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_es&type=PROGRAM&Expires=1477924208&Signature=LCa-fTKJsFxLqSKvCz0fUcK1vygTxFXkGm2AYb~q9T2m0MD8cApxki8RJ0Fa4lD6AB4~ED3D86NqLtBngz81cW6~hJCJgOW3B6CTsf8bhGcM5Zwkp7PfV-b2abY1D97YZ5RfN-BYm5sXcM7zLt8fwIbD2ZSGy-sj-wYitevvG~U_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=POILoaderforWindows_272.exe

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_br&type=PROGRAM&Expires=1441944077&Signature=fNdNpbAVveUXRq8X-q1Hbb0ROa4r33wYodeb9XCBF4obGeDg~9hMCJcv3Gzj7OSLpRqV1RTgdw9lfGfUpwn1y6h8p7SwSw3tkgc5~dlG5TDoweraeQIHcOcOcn9v5HN8kZxIV2bwfJ1dwx243uz5orzDcohRQbmDQnv9Jdz0vkQ_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=POILoaderforWindows_272.exe

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_es&type=PROGRAM&Expires=1478812750&Signature=LlIPDD7sHkgNzO3-hktdMVxUr0YSgQWa4fB7xtATsgLHaYo1~gOF6~UYODsiVsYQ2D~Xivv-rQNG3JctLpn2iWYPfdgB88lbG5Y45~2MtaVt-XqhieTkEjV1OERZdT4hJ6oDQAJE5-Xlcydd1S7xKDkYfU0CWAv89LjRvhUuVJs_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=POILoaderforWindows_272.exe

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_es&type=PROGRAM&Expires=1445834255&Signature=EjHaitQ0ffFOrMDZmWBCEGFKBsD9tzo3FOqdzvhWv4gd~maUnyV0LrVZ9sl2iER5xAk96-q9wrx94dWYuDNrbmGDo~YCupKJhShYy02ke91--gpte58-SJyAt2U0rI70n9JqooNLBlK54-yBJWC3fpCtvX4EbUeFWWOZZleZ~CM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=POILoaderforWindows_272.exe

http://gsf-cf.softonic.com/811/11a/.../file?SD_used=0&channel=WEB&fdh=no&id_file=92154&instance=softonic_es&type=PROGRAM&Expires=1437434282&Signature=LAv7GxECF4TSjJ8257qjAYKBkhZgetIyaWX6BFI6QyqsIDrApxCa~GMbQOG05nuw8FYnBr-~dmp4dNsc2B56ClZB4NxzbzwQOJitRahjvhFzGW1jEvdRnXI7B1~KpJsirq5I~b4utyq9zyK~-xZ4rfy0RgzHVz9eaqivFwX1iXI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=POILoaderforWindows_272.exe

about:internet

Latest 30 of 31 download URLs