download-(support+adorage)-adorage-vol13demo64bit.exe

proDAD Application Downloader

proDAD GmbH

Publisher:
proDAD GmbH  (signed and verified)

Product:
proDAD Application Downloader

Description:
Download files from www.prodad.com

Version:
1, 0, 1, 2

MD5:
54f37f25e16b11a85c01f95c2c361503

SHA-1:
add1c9019a2a2fb590af899b997a8273a3ae5bdf

SHA-256:
1741e4f7ce6cc80dcebe448f7dc3434ec7fae77cad8e5a026f3a9737bcb841fa

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 3:21:08 PM UTC  (today)

File size:
397.6 KB (407,104 bytes)

Product version:
1, 0, 1, 2

Copyright:
Copyright (C) 2008

Original file name:
FileDownloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\download-(support+adorage)-adorage-vol13demo64bit.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/26/2007 7:01:47 AM

Valid to:
2/26/2010 7:01:47 AM

Subject:
E=webmaster@prodad.de, CN=proDAD GmbH, O=proDAD GmbH, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
01000000000110FCDAE00C

File PE Metadata
Compilation timestamp:
11/27/2008 12:59:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:8XpB0LdxYG/2Hzj2LbmhpF56dTViF0K73ojDuUlPYa:8pGePAqpF5AJ4eDuUlz

Entry address:
0x14915

Entry point:
E8, 2C, 57, 00, 00, E9, 17, FE, FF, FF, B8, 67, AB, 41, 00, A3, 74, E1, 43, 00, C7, 05, 78, E1, 43, 00, 63, A2, 41, 00, C7, 05, 7C, E1, 43, 00, 21, A2, 41, 00, C7, 05, 80, E1, 43, 00, 55, A2, 41, 00, C7, 05, 84, E1, 43, 00, CB, A1, 41, 00, A3, 88, E1, 43, 00, C7, 05, 8C, E1, 43, 00, E1, AA, 41, 00, C7, 05, 90, E1, 43, 00, E1, A1, 41, 00, C7, 05, 94, E1, 43, 00, 4B, A1, 41, 00, C7, 05, 98, E1, 43, 00, DA, A0, 41, 00, C3, E8, 9B, FF, FF, FF, E8, 83, 62, 00, 00, 83, 7C, 24, 04, 00, A3, 0C, 12, 44, 00, 74, 05...
 
[+]

Entropy:
6.1479

Code size:
176 KB (180,224 bytes)

The file download-(support+adorage)-adorage-vol13demo64bit.exe has been seen being distributed by the following 28 URLs.

http://freedownloadsapps.com/download_now.asp?d_fname=vitascene-starterkit&fno=33818

http://www.prodad.de/.../Download-(1)(support vitascene)-vitascene-10-service.exe

http://www.sonycreativesoftware.com/.../link?id=6632.1

http://www.download3k.es/DownloadLink2-Adorage-Starterkit.html

http://www.prodad.de/.../Download-(1)(support heroglyph)-heroglyph-40-demo64bit.exe

http://www.prodad.de/.../Download-(1)(support adorage)-adorage-30-service64bit.exe

http://www.prodad.de/.../Download-(1)(support heroglyph-2.0)-Bg8Kw49_creativepack1.exe

https://www.prodad.com/srv/redirect/520fb09d?u=http://www.prodad.de/.../Download-(1)(support adorage)-adorage-vol13demo64bit.exe&t=1