herdprotectscan_setup.exe

herdProtect Anti-Malware Scanner

Reason Company Software Inc.

Warning, this is an unsigned version of herdProtect and might be compromised. If you have this version on your PC please remove it and install a legitimate version from our website.
This is a setup and installation application. The file has been seen being downloaded from doc-08-ao-docs.googleusercontent.com and multiple other hosts.
Publisher:
Reason Company Software Inc.

Product:
herdProtect Anti-Malware Scanner

Version:
1.0.3.5"

MD5:
1d116b62f3b8437a7364b0bff6928558

SHA-1:
8c2b89253ce0afd1108bd4b5cda9fc5d9a47340a

SHA-256:
a7a8cb08b9a99288603b0ecf1a0a9a67671edbec1bfe2c288159dd25dd4d8353

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

False Positives:
A number of engines detected this file but were erroneous detections (false positives).

Analysis date:
11/23/2024 10:32:39 AM UTC  (today)

File size:
2.2 MB (2,344,736 bytes)

Product version:
1.0.3.5"

Copyright:
Copyright Reason Company Software Inc.

Trademarks:
herdProtect is a Trademark of Reason Company Software Inc.

File type:
Executable application (Win64 EXE)

Language:
English (United States)

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:wtKxrLMSHZP5jy14oqwVwOiaWla4fngImVq9O4VdU16jfU4rP:7ZMS5PnmJ74fgfcDzUyP

Entry point:
55, 8B, EC, 83, C4, E0, 33, C0, 89, 45, E0, 89, 45, E8, 89, 45, E4, 89, 45, EC, B8, 54, 80, 40, 00, E8, 12, BE, FF, FF, 33, C0, 55, 68, 20, 82, 40, 00, 64, FF, 30, 64, 89, 20, B8, A8, 91, 40, 00, B9, 0B, 00, 00, 00, BA, 0B, 00, 00, 00, E8, 5C, EF, FF, FF, B8, B4, 91, 40, 00, B9, 09, 00, 00, 00, BA, 09, 00, 00, 00, E8, 48, EF, FF, FF, B8, C0, 91, 40, 00, B9, 03, 00, 00, 00, BA, 03, 00, 00, 00, E8, 34, EF, FF, FF, B8, DC, 91, 40, 00, B9, 03, 00, 00, 00, BA, 03, 00, 00, 00, E8, 20, EF, FF, FF, A1, 10, 92, 40...
 
[+]

Developed / compiled with:
Microsoft Visual C++

The file herdprotectscan_setup.exe has been seen being distributed by the following 38 URLs.

Latest 30 of 38 download URLs