datarescueprofessional.exe

DataRescueProfessional

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from en.softonic.com and multiple other hosts.
Publisher:
DataRescueProfessional

Product:
DataRescueProfessional

Description:
DataRescueProfessional Setup

Version:
3.2.0.101

MD5:
21b7f98e29d400fa8a82046574aef6f3

SHA-1:
4226793f6194e013c4a2f0b3941b7d8623d77f17

SHA-256:
51c6763cb513452f87221a58a005638ec6c41dd2bd3c87babc39171d44e0e2ca

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/27/2024 2:57:24 AM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM06.1.Malware.Gen
1.0.0.1120

File size:
1.7 MB (1,746,521 bytes)

Product version:
3.2.0.101

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\datarescueprofessional.exe

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:O9/DNm7gY8YUhvoPVC8dZGqrLLrjTSTCwp1Nvmu5q:o/DNm7bUA91P3XC/Y0q

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9451

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file datarescueprofessional.exe has been seen being distributed by the following 13 URLs.

http://en.softonic.com/sads/tracker.php?ev=c&co=IN&sid=55cc4180bdd9f6900cf15a3f6fd1b5a5&upv=90ca2566605d6cc798550e446c2dfdf1&z=results&sk=0&abp=0&params=F39B2A32BFC101987B1458170C278E032123FF0E09F5565AD6A3C9E074A2DA098D8A318D5BE1076F36EF168AEBDD85F5AE938BF0B25E139BF9C0182CF237293F3DD50E747ED36C4D9F35AE45E7E7BAD68998F24423F273CC3BC0C8B6DDA209B47242801D72203C7A77E69BF065C8D55694F0C4669C470F920CFDCA670D195825B7123DFE1E531E0808C768A7A33446972F11954E1F8450017ABCDF689E7623BBD9520D3E3BC521DA4655EC9D500A5C6A&h=045786E70D10A32CE5D9B36ED0393CDFBD160DB5546E1D5D0AE2C0A829808F37&directdownload=1&f=69711709&d=http://datarescueprofessional.com/.../DataRescueProfessional.exe

http://gsf-cf.softonic.com/422/679/.../DataRescueProfessional.exe

http://en.softonic.com/sads/tracker.php?ev=c&co=SA&sid=dcd5281a51a61101fffe73423a5e0acc&upv=b4ac7d29d9a9ab651eed05639a90c2a9&z=results&sk=0&abp=0&abt=1&eid=SWH-1830&params=F39B2A32BFC101987B1458170C278E032123FF0E09F5565AD6A3C9E074A2DA098D8A318D5BE1076F36EF168AEBDD85F5AE938BF0B25E139BF9C0182CF237293F432707D2FFF5463F5B0904557F394D348AC148E1FF77159FD1666F591ADEF5B7144103FE64EABB0B03B32AC1C8A6A80E14508043A0C4C8FB1FCF980349611502BE4A4F5226DC4F46676392DFA10C8D86B53252245051E5A9BAD9E1E96619006B46367BE9E9BF3AA561601BE26CEE65EB&h=CEAC97DADEDE598DBA643A06495EB6AF95E200742636A5E6A7F651B90052E0D9&directdownload=1&f=69711709&d=http://datarescueprofessional.com/.../DataRescueProfessional.exe

Scan datarescueprofessional.exe - Powered by Reason Core Security