f_00d578

herdProtect Anti-Malware Scanner Portable Edition

Reason Company Software Inc.

Warning, this is an unsigned version of herdProtect and might be compromised. If you have this version on your PC please remove it and install a legitimate version from our website.
The file has been seen being downloaded from oficina.egosystems.com.ar and multiple other hosts.
Publisher:
Reason Company Software Inc.

Product:
herdProtect Anti-Malware Scanner Portable Edition

Description:
herdProtect Anti-Malware Scanner (Portable Edition)

Version:
1.0.3.9

MD5:
e8cd7d40ac25ab4e28df71ccb55b0579

SHA-1:
ec3e8de5acaa62fc56f2f062847c00342116466d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

False Positives:
A number of engines detected this file but were erroneous detections (false positives).

Analysis date:
11/23/2024 8:04:10 AM UTC  (today)

File size:
2.7 MB (2,827,152 bytes)

Product version:
1.0.3.9

Copyright:
Copyright Reason Company Software Inc.

Trademarks:
herdProtect is a Trademark of Reason Company Software Inc.

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\temp\webkit\cache\f_00d578

The file f_00d578 has been seen being distributed by the following 50 URLs.

http://oficina.egosystems.com.ar:8888/PROGRAMAS/.../herdProtectScan_Portable.exe

https://cdn.discordapp.com/attachments/203952296516648960/.../herdProtectScan_Portable.exe

ftp://192.168.1.251/share/.../herdProtectScan_Portable.exe

https://onedrive.live.com/download.aspx?cid=4C2D9E99696527E8&resid=4C2D9E99696527E8!212709&canary=W8H8A NPNkPvnb4zAfhOZgSpWIu6KS PvRs4TKRvZZo=0&ithint=.exe

http://www.nonags.org/.../dfa.asp

https://www.dropbox.com/pri/get/.../herdProtectScan_Portable.exe

https://doc-0k-28-docs.googleusercontent.com/docs/securesc/mfrd315mg54rsuo18erh404q06dqe6n2/p06e6pu5v415ueaob1uo91h92n494654/1479506400000/09678150908517115224/.../0BxkoRpT0URm7OVlhNHRlZHZncVE?e=download

https://onedrive.live.com/download.aspx?cid=5FCEBED9FB112BDE&authKey=!AiD0j_s5k2k7gZ8&resid=5FCEBED9FB112BDE!13493&canary=Bptyh2GHS1gh01ZoVAhFTMZdNng84RCJlXgyKtoI1tA=6&ithint=.exe

https://www.google.com/url?hl=en&q=http://www.herdprotect.com/.../herdProtectScan_Portable.exe&source=gmail&ust=1480336214871000&usg=AFQjCNFwGjFC9Wpq1H0c2-CHsXvUxRYpbA

http://l.facebook.com/l.php?u=http://www.herdprotect.com/.../herdProtectScan_Portable.exe&h=AAQHH4zD7

http://ks1.sagaoutsourcing.com/vsaPres/web20/core/Downloader.ashx?displayName=herdProtectScan_Portable.exe&filepath=/ManagedFiles/.../herdProtectScan_Portable.exe

http://redirect.viglink.com/?format=go&jsonp=vglnk_147958663021015&key=51332a94507008460ab1441f024051d7&libId=ivpnehaz01000aau000DA1g1fdmo1tj4nc&loc=http://www.tomsguide.com/answers/id-3170696/malware-infested-google-chrome-double-search-bar-popping.html&v=1&out=https://www.herdprotect.com/.../herdProtectScan_Portable.exe&title=Malware infested in Google Chrome. Double search bar popping up - Malware - Antivirus / Security / Privacy&txt=https://www.herdprotect.com/.../herdProtectScan_...

https://www.google.com/url?hl=en&q=http://www.herdprotect.com/.../herdProtectScan_Portable.exe&source=gmail&ust=1480924720701000&usg=AFQjCNFNFf9HGFuH_ISpiONGm2waa9GGQA

http://webmail.wowway.biz/hwebmail/services/go.php?url=http://www.herdprotect.com/.../herdProtectScan_Portable.exe

http://192.168.0.3/.../10. herdProtectScan_Portable.exe

Latest 30 of 81 download URLs