videopadsetupsoftonicfr.exe

NCH Software

This is a setup program which is used to install the application. The file has been seen being downloaded from www.softonic.fr and multiple other hosts.
Publisher:
NCH Software  (signed and verified)

MD5:
616ad2cd66b374534cfc4198f64d93c5

SHA-1:
845aa34b84cc52d3e7ffbca1f6b384b52920f6ef

SHA-256:
8688a7dc6f2b0d389cd48ef16569c2cc08cda212214654ec6eda62dc10122fa5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 6:37:49 PM UTC  (today)

File size:
5.5 MB (5,814,328 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/20/2013 2:00:00 AM

Valid to:
8/8/2015 1:59:59 AM

Subject:
CN=NCH Software, O=NCH Software, L=Canberra, S=Australian Capital Territory, C=AU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6A560820FA3E9AD8E5411734B1D40AD5

File PE Metadata
Compilation timestamp:
8/23/2012 6:52:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:jKFBvzodLvTwbweNJzBV/ny20jjs42IN4SqMFUHVwf+UFNTOQCVEfhghbPH:ejzKvBEBV/ya42IN4OyHV5yN/CEfhSPH

Entry address:
0x209B

Entry point:
55, 8B, EC, 81, EC, 20, 04, 00, 00, 56, 57, 6A, 63, 8D, 75, F0, E8, AB, FF, FF, FF, C7, 45, FC, 01, 00, 00, 00, 8D, 85, E4, FC, FF, FF, 50, 68, 04, 01, 00, 00, FF, 15, 14, 10, 40, 00, FF, 75, FC, 8D, 85, E8, FD, FF, FF, 68, 60, 10, 40, 00, 50, FF, 15, 40, 10, 40, 00, 8D, B5, E4, FC, FF, FF, 8B, C6, 83, C4, 0C, 8D, 48, 01, 8A, 10, 40, 84, D2, 75, F9, 2B, C1, B9, 02, 01, 00, 00, 3B, C1, 76, 02, 8B, C1, 33, D2, 85, C0, 76, 31, 8A, 0E, 46, 84, C9, 74, 0C, 88, 8C, 15, EC, FE, FF, FF, 42, 3B, D0, 72, ED, 85, C0...
 
[+]

Developed / compiled with:
Microsoft Visual C++

The file videopadsetupsoftonicfr.exe has been seen being distributed by the following 9 URLs.

http://www.softonic.fr/sads/tracker.php?ev=c&co=FR&sid=f800f957851940deab58859f2e1d6c2e&upv=97cb3491703d46779e88563f79558f3e&z=results&sk=0&abt=1&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA6AC6EDE30E6DCD8E811D224D8A49775011E83F5A2EA528139378D6639244EE26ED97CDF5A7F58823C3F074F6AF08EA4789B6CD1315EE54F7BC794D44CFA7BB031CE6277E175CBE292C47282553D8528B15D0729F794AE16BDFF75C6D335F19D88E46EBC150D0B2ABE0E5BA3BD237DD706F00036A417B7E3695A5B07CD0AFA982C9A98F9D393984EBA9B58D611F06ECAE&h=7F9D95701D3F6F163B92BCEDE4744C413E8520F174F8D724A8072BEF86EF0CAD&directdownload=1&f=78069&d=http://www.nchsoftware.com/.../videopadsetupSoftonicFR.exe

http://www.softonic.fr/sads/tracker.php?ev=c&co=FR&sid=0dd5c1defe6203d001e7d0019ae8c609&upv=05541acc6d35a2abd16d98260af6f49e&z=results&sk=0&abt=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA6AC6EDE30E6DCD8E811D224D8A49775058B0E944F788C1BFB301247D82DA33041584DFBB6CAF3134D986329403417DA25C28D43DEA3AE7E82BC3D2DBEE5E38E569D43266D0F1126DD8F41F0384C65CF49F37F740CBBF3000D7867308D6950C65D35A8BFB52558902BCF8D9F88E4E966F1D7377E8B3EADD8BB286C0E2D4D126EDD7F66A79671BA15FC9AC02889EA82845846ECE1477C7D82989B1480E0980AF00&h=BFE08BF22CBEE61659279F7E7F99F6CA21DB8378FA926D1618F3793AE9CCFBB8&directdownload=1&f=78069&d=http://www.nchsoftware.com/.../videopadsetupSoftonicFR.exe

http://www.softonic.fr/sads/tracker.php?ev=c&co=FR&sid=b90e748d835e8291ea8ac209e007a023&upv=56ec3b1d9ab49daf231e0ec2c5d90c05&z=results&sk=0&abt=1&eid=WEB-28197-FR&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA6AC6EDE30E6DCD8E811D224D8A497750451558C7FD672AC35BFEAF92AD5D644DC73E1B9F768A0813BD41F0468A79D433C5C584DE312922B08D56BEFD1D3E05C7B4EB0C36354A0050EBFE9EF3A22801979815E2217A6D4EB105FACFF45BFAC6161E6916025D979A1DA2C63ED723431B5CA313B26C92C37E443B2D194B31D7CD020404E2BE6D558164D9F66908E94C687799B364B0AAF27975177E2C28B84D7826&h=AC7E6CB563E3E03A052B6E099020C175A2842D5FE5034AC09F8C1F0CF9F7E7F2&directdownload=1&f=78069&d=http://www.nchsoftware.com/.../videopadsetupSoftonicFR.exe

Scan videopadsetupsoftonicfr.exe - Powered by Reason Core Security