herdprotectscan_setup.exe

herdProtect Anti-Malware Scanner

Reason Company Software Inc.

Warning, this is an unsigned version of herdProtect and might be compromised. If you have this version on your PC please remove it and install a legitimate version from our website.
This is a setup and installation application. The file has been seen being downloaded from dl-web.dropbox.com and multiple other hosts.
Publisher:
Reason Company Software Inc.

Product:
herdProtect Anti-Malware Scanner

Version:
1.0.3.9

MD5:
7fb0a595b42813655a948821b5fb7566

SHA-1:
729df8e56e37f5347ecb2de77ba0ff3074b010e4

SHA-256:
3cbdf0b5a79dfb12a1bf30906a0903ea0cf316c94677bf863af9069bb27e79ee

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

False Positives:
A number of engines detected this file but were erroneous detections (false positives).

Analysis date:
12/26/2024 7:56:12 AM UTC  (today)

File size:
2.4 MB (2,515,504 bytes)

Product version:
1.0.3.9

Copyright:
Copyright Reason Company Software Inc.

Trademarks:
herdProtect is a Trademark of Reason Company Software Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
8/24/2001 8:30:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.55

CTPH (ssdeep):
49152:t51UxrOxRjdlmJ0KzAL6izxiSbFl/tdfngImVq9O4VdU16jfU4V:VU85dIJ0ulizjbb/jfgfcDzUW

Entry address:
0x11F0

Entry point:
55, 89, E5, 83, EC, 08, 83, C4, F4, 6A, 02, A1, C8, B2, 40, 00, FF, D0, E8, 79, FF, FF, FF, C9, C3, 00, 00, 00, 00, 00, 00, 00, 49, 01, 23, 32, 32, 32, 21, 45, 73, 62, 68, 70, 6F, 21, 77, 6A, 73, 76, 74, 2F, 21, 43, 70, 73, 6F, 21, 6A, 6F, 21, 62, 21, 75, 73, 70, 71, 6A, 64, 62, 6D, 21, 74, 78, 62, 6E, 71, 2F, 00, 5C, 00, 20, 00, 22, 00, 8D, 76, 00, 55, 89, E5, 8B, 4D, 08, 8B, 55, 0C, 31, C0, 39, D0, 73, 08, 00, 04, 08, 40, 39, D0, 72, F8, C9, C3, 8D, 76, 00, 55, 89, E5, 8B, 4D, 08, 8B, 55, 0C, 31, C0, 39...
 
[+]

Entropy:
7.9249

Packer / compiler:
Video-Lan-Client

Code size:
32.5 KB (33,280 bytes)

The file herdprotectscan_setup.exe has been seen being distributed by the following 16 URLs.

http://113.171.224.177/.../herdProtectScan_Setup.exe