pokersetup_23d676.exe

Playtech Software Installer

Playtech Software Limited

This is a setup and installation application. This is the uninstaller utility registered in the Windows Control Panel for the program Ladbrokes Poker. The file has been seen being downloaded from banner.ladbrokes.com and multiple other hosts.
Publisher:
Playtech  (signed by Playtech Software Limited)

Product:
Playtech Software Installer

Description:
Ladbrokes Poker

Version:
11.2.38.0

MD5:
74e273d8831e56c6fbc1a4b858702250

SHA-1:
6b3ea7ced3f5bd7b1a42a900d0d2d9c670e19969

SHA-256:
5e2b522bed11f9b9cf1ca94daf65dfbad4150233acc8cfe88a94b2dcb8953196

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 5:15:41 AM UTC  (today)

File size:
446.8 KB (457,528 bytes)

Product version:
11.2.38.0

Copyright:
Copyright (C) 2001-2009 Playtech

Original file name:
CasinoDownloader2.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\pokersetup_23d676.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/22/2012 4:00:00 AM

Valid to:
10/27/2015 3:59:59 AM

Subject:
CN=Playtech Software Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Playtech Software Limited, L=Douglas, S=Douglas, C=IM

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7584CAA2377ED24D26D91034E6DE0EBB

File PE Metadata
Compilation timestamp:
12/13/2012 6:21:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:2jQBTTO+USClWquIed81HjjPbbBpb/BQa2sCB5RlVqUu:KQBTSw4vHfTbXbvNCBpVHu

Entry address:
0x348BC

Entry point:
B8, 50, 36, 61, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 69, E9, 06, E1, 14, 8A, 82, 88, A4, 55, A1, D3, 71, C0, CD, D0, E1, 14, 66, 68, 14, 2D, D5, 69, F9, FE, 01, C6, CB, E7, A2, F1, 07, 1F, F1, ED, 6C, C9, 65, 52, 1F, 60, 46, B1, A5, A4, FA, E4, 5A, 32, 86, CB, E4, 11, BF, 37, FA, F4, 11, 8B, 78, 29, DB, F5, 19, 51, 2B, 9A, 10, 20, 3D, 1C, 99, 78, 03, A3, BB, 3E, 97, F1, EA, C1, 86, 7F, 2F, 86, 7C, 4A, 02, 28, 15, 1C, B9...
 
[+]

Entropy:
7.4775

Packer / compiler:
PECompact v2

Code size:
335.5 KB (343,552 bytes)

Program Uninstaller
Program name:
Ladbrokes Poker

Uninstall string:
"C:\Poker\Ladbrokes Poker\_PokerSetup_23d676 (1).exe" /uninstall


The file pokersetup_23d676.exe has been seen being distributed by the following 4 URLs.

Scan pokersetup_23d676.exe - Powered by Reason Core Security