expressburnrefsetupsoftonicen.exe

NCH Software

This is a setup program which is used to install the application. The file has been seen being downloaded from en.softonic.com and multiple other hosts.
Publisher:
NCH Software  (signed and verified)

MD5:
227e9d52eec194f0b1ddf7307964950a

SHA-1:
0bfce03b8568ec192c5f09a88b69f85afee6a0b7

SHA-256:
f7a50fabfd5075114ac005cbde48226869d8c95d48537686a42266744851fa9c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 4:24:23 AM UTC  (today)

File size:
835.8 KB (855,840 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\expressburnrefsetupsoftonicen.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/5/2015 8:00:00 PM

Valid to:
8/6/2017 7:59:59 PM

Subject:
CN=NCH Software, O=NCH Software, L=Canberra, S=Australian Capital Territory, C=AU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
58D9B9D38780932DD1CBC58A2AD28B1C

File PE Metadata
Compilation timestamp:
9/30/2014 8:46:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:A/U10IRP+Gfa7V81mZbfd6Yt10FJDKw4++uyHfRq/:t0CPZy7VTZbf3toBnifo

Entry address:
0x209B

Entry point:
55, 8B, EC, 81, EC, 20, 04, 00, 00, 53, 56, 57, 6A, 63, 8D, 75, F0, E8, AA, FF, FF, FF, C7, 45, FC, 01, 00, 00, 00, 33, DB, 8D, 85, E4, FC, FF, FF, 50, 68, 04, 01, 00, 00, FF, 15, 1C, 10, 40, 00, FF, 75, FC, 8D, 85, E8, FD, FF, FF, 68, 64, 10, 40, 00, 50, FF, 15, 44, 10, 40, 00, 8D, B5, E4, FC, FF, FF, 8B, C6, 83, C4, 0C, 8D, 48, 01, 8A, 10, 40, 3A, D3, 75, F9, 2B, C1, B9, 02, 01, 00, 00, 3B, C1, 76, 02, 8B, C1, 33, D2, 3B, C3, 76, 31, 8A, 0E, 46, 3A, CB, 74, 0C, 88, 8C, 15, EC, FE, FF, FF, 42, 3B, D0, 72...
 
[+]

Entropy:
7.9820

Developed / compiled with:
Microsoft Visual C++

The file expressburnrefsetupsoftonicen.exe has been seen being distributed by the following 13 URLs.

http://en.softonic.com/sads/tracker.php?ev=c&co=CA&sid=83831f37ee586e31b4396a6bef0ce4c4&upv=46e6e408260ce2814d886ea34b663954&z=results&sk=0&abp=0&params=F39B2A32BFC101987B1458170C278E039F6B6B2BA644DDB1A95F6B1539046BFD29DF7731BE0E6BD23C2813064D9846360B25D9873DCE3081A8C314CC6973840ACF210F0BF6952108339839FB662E3657DCA4B111DA36F10123EF551799333633FCBABDABF97839818AE76FD668233675E3663D0C0701C2B2EB167BDF5A3E740630998704CAF7643EA4F63544B423915F229015AF36E28B1273631C7D82D99949&h=02B37C37F215CFA20FA5FBD91C15644A905320BD04619BCA0B788157E1816F8E&directdownload=1&f=37345&d=http://www.nchsoftware.com/.../expressburnrefsetupsoftonicen.exe

http://en.softonic.com/sads/tracker.php?ev=c&co=CA&sid=7e8548d8bddf6b42c096a278f140c9ba&upv=6c47c6c2e19aa232485c09b5c21796fd&z=results&sk=0&abp=0&params=F39B2A32BFC101987B1458170C278E039F6B6B2BA644DDB1A95F6B1539046BFD29DF7731BE0E6BD23C2813064D98463669392F009BCBF129DE42B3B7BEF04593D4112BC1B1757BA258FBDA33EF77BE280B81340F9254014815F72FD4D05B84C86C4AEF8E78296E525AB1B6BC453BA6890772633927F985EFA16623A57BAFC0ABC75B8B7B6AD17904BD169DAA644ECA6411D48B8FD79845310CC0A18296B54599&h=9197492D6741AECCB45F86C301D85A67E3CB8D625893B4B6827BD54556802FBF&directdownload=1&f=37345&d=http://www.nchsoftware.com/.../expressburnrefsetupsoftonicen.exe

Scan expressburnrefsetupsoftonicen.exe - Powered by Reason Core Security