d3htjhr0eb3qn6c+vvxeqvve0t4=_itunes64setup.exe

iTunes

Apple Inc.

This is a setup and installation application. This is installed with iTunes. The file has been seen being downloaded from secure-appldnld.apple.com and multiple other hosts.
Publisher:
Apple Inc.  (signed and verified)

Product:
iTunes

Description:
iTunes Installer

Version:
11.0.5.5

MD5:
57ed2e029bf9ca39383d2a671ef4fb50

SHA-1:
7771ed8e147411bdea37a73ebd5c5ea9555ed2de

SHA-256:
9db398a8115f2d30815609f49fcba77fc6090ea55842f7bce544d608613b76a2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 10:32:47 AM UTC  (today)

File size:
86.7 MB (90,889,040 bytes)

Product version:
11.0.5.5

Copyright:
© Apple Inc. All Rights Reserved.

Original file name:
iTunesSetup.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\gfi\languard 11\repository\english\d3htjhr0eb3qn6c+vvxeqvve0t4=_itunes64setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/24/2013 12:00:00 AM

Valid to:
7/23/2015 11:59:59 PM

Subject:
CN=Apple Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Apple Inc., L=Cupertino, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47DE2F9FBF7A1D4191F45773FA113E1D

File PE Metadata
Compilation timestamp:
8/16/2013 4:43:33 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1572864:JQAnyW1X+GQrVsBoPfAVCzEI4mGtdgq06PLQXyYtwi2oH:J/ny4OGks44dGGYbwiXH

Entry address:
0xDF28

Entry point:
48, 83, EC, 28, E8, 97, 50, 00, 00, 48, 83, C4, 28, E9, 1A, FE, FF, FF, CC, CC, 48, 89, 0D, ED, F2, 00, 00, C3, 40, 53, 48, 81, EC, E0, 05, 00, 00, 83, 64, 24, 70, 00, 48, 8D, 4C, 24, 74, 33, D2, 41, B8, 94, 00, 00, 00, E8, 6C, C9, FF, FF, 4C, 8D, 5C, 24, 70, 48, 8D, 84, 24, 10, 01, 00, 00, 48, 8D, 8C, 24, 10, 01, 00, 00, 4C, 89, 5C, 24, 48, 48, 89, 44, 24, 50, FF, 15, 57, 72, 00, 00, 48, 8B, 9C, 24, 08, 02, 00, 00, 48, 8D, 54, 24, 40, 48, 8B, CB, 45, 33, C0, E8, 19, 68, 00, 00, 48, 85, C0, 74, 3B, 48, 83...
 
[+]

Entropy:
7.9998  (probably packed)

Code size:
79 KB (80,896 bytes)

The file d3htjhr0eb3qn6c+vvxeqvve0t4=_itunes64setup.exe has been discovered within the following programs.

iTunes  by Apple Inc.
Apple's iTunes is a proprietary media player computer program, used for playing and organizing digital music and video files on desktop computers. It can also manage contents on iPod, iPhone and iPad.
www.apple.com/itunes
9% remove it
TeamSpeak 3 Client  by TeamSpeak Systems GmbH
Publisher's description - “TeamSpeak 3 continues the legacy of the original TeamSpeak communication system previously offered in TeamSpeak Classic (1.5) and TeamSpeak 2.”
www.teamspeak.com
4% remove it
 
Powered by Should I Remove It?

The file d3htjhr0eb3qn6c+vvxeqvve0t4=_itunes64setup.exe has been seen being distributed by the following 44 URLs.

https://secure-appldnld.apple.com/iTunes11/.../iTunes64Setup.exe

http://filehippo.com/download/file/.../

https://dw.uptodown.com/dwn/hvhJz1s5o3h1Kc9XyViyo9pGy5ZUQJhiA8nE5xDO62AhTa5aK1BIh90Y9-R_cJXzkU-FyqMgzW12tMh6k02op8I6oz0ciEXJ1hpMJgQPPD1N5TYBS0_Lyfjr-X4hOxFB/kxHEvk789LKkkvyUNVt1NmVf5OOcH5WHVeHY1IZWOP81QSX2thYTI5nTIHOUUOr5FTyShOm4WuJr-0IfzWFyJE3_zbKnj_7ncGQ9OkzN26rMZ8j3t74RlEPtfAhOWnOE/TUXF6DOslkHuCCTmY-WUZHtAHM1n8GR8kBteHmPV0DFUTYnWTKv6b56ax9aYqDOwWGGxs-t1FUcDrdTPDETWnJXV1lwnKVa2RJ6ExYtPtLyZGnsuP1mItVPNm4wEcEJm/.../

http://www.filehorse.com/download/file/.../

https://dw.uptodown.com/dwn/h72k1ncbzfYn5wNCnS1y94zYaKEmKJZNZwkeMraAhzmquOvDZeBCt2KCI6WeMHizA12q21N_FBjXZtNZw6jNXoacLzPZSKyiiWlnu7Ep-b-4mLrE6k4JnIuZijD46AR8/_OsDdvt2XTsxSSsE9REoRF1OCcxdDDJXBUDhhsRGFUDplzoLZn6tEJUnQusITwOyJhRTn2AMFq4vyd1PI3nwVyXOJpzl_MKApl-i8OgEJuYlsVsbB1H38WgrKyLDA-nB/zbcwrZA3oItc6CfO9FOw8i7hpXoPiqwTG46AUL-m4LxmYnvlSw496BmN2wdavp0x7d3KqiKcM70HJ12moQrWOL0XV-mCgZLQHCVu2um9mHwdTKnIay2k--cQjuowySE-/.../

https://dw.uptodown.com/dwn/0tKi46x2KVgydygZuqkKGNezKyD5-4kmjcZShWpnsEAf0iU3bdidH766SNbs78bx-FeuWAkcgAFg6YfYv5xUbwlJEc-Ru83zS3--I0v_HoAaiKNcmSsPMpDdfZQ0S8Fh/xo7iFtB8Jo-v-7xvr3pqCq-yGDe6z0Qs5NtydddeXpXlrXATQMVS-zjy0qmPab0mrCjLuIsL7YsHDXInW_4Th1A9ALXxsJ2ILYwrIkOokvPC7phGhEGWXj-Yf4D2sJHp/Zaz5GrZR-s8NUlNN1Mam6is5yyuGluWpq5F7FBLAe2SzVH8Kv3ks3FLYsZIwcWORDjabjV7MkCdYti7uhWwk6F7mvf8xfGgrvPNfYsbXD4cg2uvqOZ2MF9_8LESX4ySX/.../

https://dw.uptodown.com/dwn/j2DrY1BJV3tJH8ohhlM5m1ElDH4VXOKizzl1BrClKRC4US4CrAlQzjD42bo20u_ubybWTTPihFmo262AVh4YJjvc5_z_7BuolFVZMFo_ooYPlDJlilIEVriYrO90-Sfs/O-SN9oggjsFGqc7VIPvOcQwSyRjx_ZF18vk9X9AAUWOPsiehuR-itN4sBP21QJ-fthXgzYO0UJgTrTPoJngOxSC4N3DI2JSoPQvapHJI_ddP0d9sZEjqCrPBfLu4jsUb/kuU7IiICtNUF2ElQ2_jqnwOJgpIkhAQC4fuzdqCwCm_FsONfZxCzWeodDJA8r2Tdm2OBgd_zb_feTzqTlH-bjoxIg3PIWVibP3oPryN4VF6zjL-Q3gv58Tmyf_O8H5eg/.../

http://filehippo.com/download/file/.../

http://turbobit.net/download/redirect/3BF7C02FDE51C3AA750D41FD61C339B3/.../iTunes_11.0.5_64bit_Setup_Mükemmelin_Blogu.exe

https://dw.uptodown.com/dwn/VA18oJG92nF8BbWmYbjmY1Qi2I7obiuCfjiNOqKF5jJy-kjZ5uB_iBHnYaFaIoBHQnTNk_mNdVikEkO89rKC3mGGXkt6onqZ9Yc3CPIvz23-yPJSSLuRxapOmzaECFhp/8JXG7LGYtOQJZzZEN4RqqVwiDCPqoHZUJbpQYpRxeN-rq4AXPYniHJIdBIp8gQ9jzWOVjKJdAtSJTui3qr2OTfN2fhaZm8uscR7VJHn2a51vv8xNbezdLQV-374kpsqc/QGULDQb1aC9l8uX5lbdMQ1avpbXkCkb3UKrmNoZ1h6pI3aUyZvjrHC30ZbI9cpiRUMkz0A-hrdfda83niJmqsgLB9v_mHzV05mtk3wRGRIq6zmlhxhD5aB2s-mHz_9Ql/.../

http://www.filehorse.com/download/file/.../

http://phanmemdownload.vn/.../download&itemId=23273&key=1e3c85491f3db177b6d8419291448391

https://dw.uptodown.com/dwn/aRe5SjSF9U1_c3jA3CtLawlD_goAe5XI8IiNx0ZR8qfcojXBbf8znBeJMmVhf3o8liBFo43tnEQMdE3o-pyCpAVHa-ptaS0OmTamgOwnX9OJRKz-8LF4_Y6GwkRvbZz0/tGoLUKsfsHeV3WfmT3e4BxYuPgzVSEoLS6Qyv1-9thl4vL-eAXNGLQCAV_8PGecfuxGwYAZ4POzfIHdD3gpKN8Y-w8UaR4fsM-QaYdIt6czKRP9mvWOjYhmJctKpaKmL/eVIXSUbd17dIZiL3iarC2wd9bhNgIapOPymS2F3ESwYmEvRc1_JFI5I-s-DEhdSvx6JHY8Kfz3sYVfmF7CvWHrgBHCVj_IQPAj8xJqP0VGi1s1_YFz4zyZ98E9PzIo66/.../

http://filehippo.com/it/download/file/.../

http://filehippo.com/es/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

Latest 30 of 44 download URLs