Setup.exe

NCH Software

This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from en.softonic.com and multiple other hosts.
Publisher:
NCH Software  (signed and verified)

MD5:
16e7950706283fbe026d509d0da4002f

SHA-1:
1ea2686c23da0ebefe0b86224f3b8a574b0e289b

SHA-256:
2591eb2cef07dd56080b202fe61dfcaee3351b29184b4f6df95582552903fc83

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 6:54:00 PM UTC  (today)

File size:
4.8 MB (5,024,512 bytes)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/5/2015 8:00:00 PM

Valid to:
8/6/2017 7:59:59 PM

Subject:
CN=NCH Software, O=NCH Software, L=Canberra, S=Australian Capital Territory, C=AU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
58D9B9D38780932DD1CBC58A2AD28B1C

File PE Metadata
Compilation timestamp:
9/30/2014 8:46:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:hWpKTg79FKQttX5+geiMkoFEYz0aE9krK/e4qdzFGdmGm5wW8oWwy:hWpkg79sY5+geianz0aEar+e1x4m5wVZ

Entry address:
0x209B

Entry point:
55, 8B, EC, 81, EC, 20, 04, 00, 00, 53, 56, 57, 6A, 63, 8D, 75, F0, E8, AA, FF, FF, FF, C7, 45, FC, 01, 00, 00, 00, 33, DB, 8D, 85, E4, FC, FF, FF, 50, 68, 04, 01, 00, 00, FF, 15, 1C, 10, 40, 00, FF, 75, FC, 8D, 85, E8, FD, FF, FF, 68, 64, 10, 40, 00, 50, FF, 15, 44, 10, 40, 00, 8D, B5, E4, FC, FF, FF, 8B, C6, 83, C4, 0C, 8D, 48, 01, 8A, 10, 40, 3A, D3, 75, F9, 2B, C1, B9, 02, 01, 00, 00, 3B, C1, 76, 02, 8B, C1, 33, D2, 3B, C3, 76, 31, 8A, 0E, 46, 3A, CB, 74, 0C, 88, 8C, 15, EC, FE, FF, FF, 42, 3B, D0, 72...
 
[+]

Entropy:
7.9991

Developed / compiled with:
Microsoft Visual C++

The file Setup.exe has been seen being distributed by the following 26 URLs.

http://en.softonic.com/sads/tracker.php?ev=c&co=US&sid=a12e078a9c7e5f3c5158314017a26f7a&upv=59541f9410ae6e144f0f1bd5f2bd95ee&z=results&sk=0&abp=0&params=F39B2A32BFC101987B1458170C278E030CD0B7A6A5C8B2C4D61D64F348D596639814F9196135AB822FFBD8F8E109D780FB4319D3406069A59F8B7BABFC34FD778BD3BAA2BAD507EB659EA97D2FB40585A8B2808F7913A69647DB7E9DA552E098D262242688A377FB76D04DA66A0150628BB84ED212BFC2A4F9B1DC77857742CB6E364E6A5AF48C9A06F4BE2153A40FC0588356331E3CC49224D1E06271C8AC64&h=CD5BFF4B54BBDCD71302BF9C00A5C18904CFCD4A1EBD4D05FB4B6004DCED51FD&directdownload=1&f=78069&d=http://www.nchsoftware.com/.../videopadrefsetupsoftonicen.exe

http://en.softonic.com/sads/tracker.php?ev=c&co=US&sid=917173f0c93c780d66ad1be65ceb7d91&upv=f0e2bb9f46bdec5a90da5571d4402188&z=results&sk=0&abp=0&params=F39B2A32BFC101987B1458170C278E030CD0B7A6A5C8B2C4D61D64F348D59663A6E4F953C38DA3886D428C13C1165DDAD57B96D7B7A881682FAF8593C6B521B424E766D2A1CD642DD57CF541D258100AB88C98A1C4C818DF0BC5CFB572A6327142269D8283942347CBEDBB6F8DF2C31C55CCEB94BE993992C15291D146F8743042C187FA3E35C799F29339D81D4422EA05CBFD1D2A125D2A80BF3FE65BAD4E2C&h=4ECAD94CA75F05B46FDA5C31AC62229526DA7AFBE52A83909F8FF7532A1AD74B&directdownload=1&f=78069&d=http://www.nchsoftware.com/.../videopadrefsetupsoftonicen.exe

Scan Setup.exe - Powered by Reason Core Security