timeleft.exe

TimeLeft

NesterSoft Inc.

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
NesterSoft Inc.   (signed by NesterSoft Inc.)

Product:
TimeLeft

Description:
TimeLeft Setup

Version:
3.59.0.293

MD5:
94d7f81a8aa20dba7d17628972b421bc

SHA-1:
9819d5953e23dc106a58f06adaad5cd6d0cdffea

SHA-256:
05e290cb6a81745b5bdf7edcb38e6d25b221039d3ec00b888b7f9e0285078487

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:07:06 PM UTC  (today)

File size:
2.3 MB (2,448,720 bytes)

Product version:
3.59.0.293

Copyright:
Copyright © 1999-2012 NesterSoft Inc.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\timeleft.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
11/19/2009 7:00:00 PM

Valid to:
11/19/2012 6:59:59 PM

Subject:
CN=NesterSoft Inc., O=NesterSoft Inc., STREET=56 Noble Prince Pl, L=Woodbridge, S=ON, PostalCode=L4H1S5, C=CA

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
550CFF8D8820F2EBD59B3B511E78B8DB

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:U2RSpoI4PSp2CSjBMQb5Wj+r46zbKUFi9oEjzeH1pzB2tm:5RSpoIihjBMQb5SB6aGi9HjzeHTFN

Entry address:
0x9B24

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, A2, 95, FF, FF, E8, A9, A7, FF, FF, E8, D4, C9, FF, FF, E8, 1B, CA, FF, FF, E8, 0E, F3, FF, FF, E8, 75, F4, FF, FF, 33, C0, 55, 68, DB, A1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, A4, A1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 02, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 04, D0, FF, FF, 8B, 55, F0, B8, E4, CD, 40, 00, E8, 53, 96, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E4, CD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.9953

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file timeleft.exe has been seen being distributed by the following 6 URLs.

http://gsf-cf.softonic.com/981/9d5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=18063&instance=softonic_en&type=PROGRAM&Expires=1443285471&Signature=Af~EtAJRCttyUvt7e1mpwAyK3UJyA2FHGzC1dDNqF~n3SHb8QanXwDBVFrwDChEnT1lGztAYggP3A5mIuDiJJPDXy~Xdnn6eBuwzkNvz4KHXpOu3Up3CQ7NER0ia3q4Fk4nLh3jB-T9lKp-gfYupao37YIjpCC~dPSH1Ww3e3iA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=timeleft.exe

http://gsf-cf.softonic.com/981/9d5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=18063&instance=softonic_en&type=PROGRAM&Expires=1422573722&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=SWTV43gUUgzRWKt18JR7BVH1QDPZ8boZ9EhoP9taUSiHTbpBGolCSF7wSHa8I3dG0WuC0LXxBm7SHU2e1qlBL0wF~hP-qH8dgILa80tw11l8~WzDDvTutsKINwGFodS-lMroP0s1UZAnWS1EiMhDhLuj~8YSZHdQ5HZbVY7oYIY_&filename=timeleft.exe

http://gsf-cf.softonic.com/981/9d5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=18063&instance=softonic_en&type=PROGRAM&Expires=1425079218&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=O1~sH9-FjyA2D4~yXcc-8L1~Cjn2Jbn5sSrrP84O2d0zfbhS9w3GuzunNJ9-EPGLCotEXoM2ObmseTzHicOMU0R-SOjfoivtub5F2-IKH-I9jG5dYnT5hz63GiyMrlmOJlhHoYDA6RE0S3yT1JKHlWz77J2zTCqZKOXWBQ9zzi4_&filename=timeleft.exe

http://gsf-cf.softonic.com/981/9d5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=18063&instance=softonic_en&type=PROGRAM&Expires=1476224167&Signature=e-ik8oK47XqWTZXLq-Azr4fQpf5s3IsS1zv1a896dnwhbGIpnivQ6usjIN4KAbdTJF7qIZgvmt8iCYID5juKMT6sBlvoUTPqb6iflNLzexUGxppvSo6tPrGgdlKC81Q6tML81datYC6yDEPZxQGCUoUHd5Um8Wckxuew1q4~yc8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=timeleft.exe

http://gsf-cf.softonic.com/981/9d5/.../file?SD_used=0&channel=WEB&fdh=no&id_file=18063&instance=softonic_en&type=PROGRAM&Expires=1443576418&Signature=O2H97MxD8KSHjLLdSO3vSgw8VahhJ3iy9gDuVAYhWDqkb7WTzHIlUnIgxJke~NAMEwbMvCnej~tM9oO~1To-Q8JXnpluImslG2LVp-iocA-quOX2yCGd0yp0Is6XO9BbZEqIPcPxmODu5xnnSX1urwMnBgcpWumSPAZcF5fSrcE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=timeleft.exe

Scan timeleft.exe - Powered by Reason Core Security