ptu209f_tmp.exe

Playtech Software Installer

Playtech Software Limited

This is a setup and installation application. This is the uninstaller utility registered in the Windows Control Panel for the program Poker at bet365. The file has been seen being downloaded from download.p365download.com and multiple other hosts.
Publisher:
Playtech  (signed by Playtech Software Limited)

Product:
Playtech Software Installer

Description:
Poker at bet365

Version:
11.2.38.0

MD5:
407d338f98d2193712cb89997f389e80

SHA-1:
2b4b0497e6053c99d1cb5c23b02e6c0180535bf0

SHA-256:
181f936446142aecced029609e48a0a802b6cdc181779f8959a97080a55782c0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/13/2018 1:13:03 AM UTC  (today)

File size:
569.8 KB (583,480 bytes)

Product version:
11.2.38.0

Copyright:
Copyright (C) 2001-2009 Playtech

Original file name:
CasinoDownloader2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\ptu209f_tmp.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/22/2012 1:00:00 AM

Valid to:
10/26/2015 11:59:59 PM

Subject:
CN=Playtech Software Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Playtech Software Limited, L=Douglas, S=Douglas, C=IM

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7584CAA2377ED24D26D91034E6DE0EBB

File PE Metadata
Compilation timestamp:
12/13/2012 2:21:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:2jQBTTO+USClWquIed81HjjP4zx0pUt83OVQ/I5LmhDngH:KQBTSw4vHfwx02tKOVIIdScH

Entry address:
0x348BC

Entry point:
B8, 30, B0, 67, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 7F, 39, 0D, B6, F2, BC, E8, F2, 5E, 8E, 23, 5B, 39, 40, 49, 4E, A6, 59, 85, 34, 2E, E7, 40, BA, 44, 6E, DA, 1A, 56, A5, 48, B0, 03, 38, 86, 3A, 3E, 18, 1A, 35, 2D, 54, 29, 20, 3E, 01, 96, 0A, B4, 26, 98, 38, 43, CE, 06, 81, 87, D4, B7, 09, 92, 96, AE, CC, 4B, 3D, 3E, DC, 22, A1, 76, 83, 7C, EC, 6B, 86, AA, 0B, 29, A3, 1C, 05, B9, F0, BB, 26, B8, E0, 40, 09, E7, 64, DA...
 
[+]

Entropy:
7.5707

Packer / compiler:
PECompact v2

Code size:
335.5 KB (343,552 bytes)

Program Uninstaller
Program name:
Poker at bet365

Uninstall string:
"C:\Poker\Poker at bet365\_SetupPoker_407fae.exe" /uninstall


The file ptu209f_tmp.exe has been seen being distributed by the following 2 URLs.

Scan ptu209f_tmp.exe - Powered by Reason Core Security