imagetopdf_setup_ad.exe

Image To PDF

zxt2007.com

The executable imagetopdf_setup_ad.exe, “Image To PDF Setup ” has been detected as malware by 7 anti-virus scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.softonic.com and multiple other hosts.
Publisher:
zxt2007.com

Product:
Image To PDF

Description:
Image To PDF Setup

Version:
1.6.0.0

MD5:
74d656c0da230ee7275eebb6ae2e345c

SHA-1:
f12f2ec769d453f28dc935c01c026e160f9e68db

SHA-256:
4cb7d863b908cad80334ee2bd4ca40f7f6d45a7a775061693bc8886537671d83

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
11/27/2024 4:22:02 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Agent.1436647
8.3.1.6

Dr.Web
Trojan.DownLoader12.54969
9.0.1.0211

IKARUS anti.virus
Trojan.Agent
t3scan.1.9.5.0

McAfee
Artemis!74D656C0DA23
5600.6688

Trend Micro
TROJ_GEN.R02SC0OFG15
10.465.30

VIPRE Antivirus
Trojan.Win32.Generic
41928

ViRobot
Trojan.Win32.A.VB.1436647[h]
2014.3.20.0

File size:
1.4 MB (1,436,647 bytes)

Product version:
1.6.0.0

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\imagetopdf_setup_ad.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:RGjAZR0RWxUunjQe7CdzYnIqIIKwWEm1JpF8Y48NFZ0PbyFudw98DU5:RqGUujQe7CF9qfFA8Y2jymy+C

Entry address:
0x9B34

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 66, 95, FF, FF, E8, 6D, A7, FF, FF, E8, 98, C9, FF, FF, E8, DF, C9, FF, FF, E8, 0E, F3, FF, FF, E8, 75, F4, FF, FF, 33, C0, 55, 68, EB, A1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, B4, A1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 02, FA, FF, FF, 8D, 55, F0, 33, C0, E8, C8, CF, FF, FF, 8B, 55, F0, B8, F4, CD, 40, 00, E8, 17, 96, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, F4, CD, 40, 00, B2, 01, B8...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file imagetopdf_setup_ad.exe has been seen being distributed by the following 23 URLs.

http://www.softonic.com/sads/tracker.php?ev=c&co=ES&sid=e072169fe685a755e572015e32a21376&upv=08f25bf0d0d4899045653576492abb10&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAE1A16743FECF3EECEB4DC3D7B3E7AEFB00808D8DF5145BA08457D44610D7CD68F88C92AFF8A0B797E4E3A0CBA7AA449167894247B3B5DEBCAEF75BF20FADD9AA9B188EA8B6459AFE2F582DFC03952009447FB7E42E5ECF1AD5F8741565AA924BE5D1481B6A1ABE0A9846E9CEC98B9014032E762BFFAE5BC45B0E72FFC970B7483B1D076E19A9FDB1F0ED479199044D39&h=4C86F045827E2355D44B0EF3F5A1A9EF13451B9845C6CA96B6341B3700DC4CC0&directdownload=1&f=3346679&d=http://en.zxt2007.com/.../imagetopdf_setup_ad.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=ES&sid=104f11bfda5aac9966abc23f5f68aa72&upv=2897aa8fd394d922400ae76dc6e82b28&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAE1A16743FECF3EECEB4DC3D7B3E7AEFB00808D8DF5145BA08457D44610D7CD68F88C92AFF8A0B797E4E3A0CBA7AA449153B8C81F681393AE8987B677FAC3C32034DC38AD34DDA133D8F8A1FB72C137568C9973D748A4BAB75CACE5469CCB4C9FFCEE2C4F9E35ED6BFA3E8CB11626B3AFF4433C482066B5F1542CB03561872C165ED28D4BCCEF24E8C3B6687EB7CC08F7&h=D99038ECCEC5AFAAADC9C9839A90A2512C4BFC0E65E969253DFEAA3052BEDEBF&directdownload=1&f=3346679&d=http://en.zxt2007.com/.../imagetopdf_setup_ad.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=CL&sid=a53cd3dd5bb07b8fc22c0db39a1f13a4&upv=d1190d991519fa24632475fcfdf9ce95&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAE1A16743FECF3EECEB4DC3D7B3E7AEFB00808D8DF5145BA08457D44610D7CD68F88C92AFF8A0B797E4E3A0CBA7AA449153B8C81F681393AE8987B677FAC3C320CC1E3FD724E4277BE84E5DE059ECC6C20C6D532EA35840326ECFA9711901CCAE794C4F1AB6A3DE746B173EA31ECF8BC8D2FD1F6164520648331DA8E5D398B193E8CA49CC288C4EE80D6BDF52C0889484&h=B16A349001315352F686674639FE5EB77275A47392EBDE51129B994B2CC957BD&directdownload=1&f=3346679&d=http://en.zxt2007.com/.../imagetopdf_setup_ad.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=e10ba093dc8e45953ce0dcf645daeb34&upv=24e7c94c4383627de950aeb16e1c78d6&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA43C7E30966742A4FB50C7DC03389F3D5EAEB2ED3D26D942E336DCB9B923DABA46F02CD6089E1EA66DECD56C94A829F795733CB1843C6DC19CD265768BFE56F092E1EC11717EDC308F55E581D5298355AA16917D7AB75ED655D08714CB166D601355881E491F8EDC74D9E6CBAA20018171005A540114B2E3B7A519679DA99AB034A4E3FEF3B531A3242CA9DDE04A0D884&h=D1044F7683770DFD3C090BED517D3907B73F50E6482CBFA2CF64377ACF9985C3&directdownload=1&f=3346679&d=http://en.zxt2007.com/.../imagetopdf_setup_ad.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=CL&sid=d3d4f8bae731b0862a6bceb672e262df&upv=a66c25992595f2f6b6e1f319f71978df&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAE1A16743FECF3EECEB4DC3D7B3E7AEFB00808D8DF5145BA08457D44610D7CD68F88C92AFF8A0B797E4E3A0CBA7AA449153B8C81F681393AE8987B677FAC3C320332F948028A3268C483924C37F9231E25204EBCA05A2E895919711BBAF5D582AA7A890EA9593A6E20AA7D0399AE76E72E687DA9ABAF5DE6C34D2BD952D9C8A4C1A832D4FD9E412827E808F894C9544D4&h=04FB5FA036437BEBE7D82066804512B2C95AB5AEA343098B1E25A456B76E4F1D&directdownload=1&f=3346679&d=http://en.zxt2007.com/.../imagetopdf_setup_ad.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=CO&sid=566156268c77d151e6b3ccbd9b8f8a68&upv=7c8485bba4a49a2d913ed43ee5895c1c&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAE1A16743FECF3EECEB4DC3D7B3E7AEFB00808D8DF5145BA08457D44610D7CD68E174C2FB6125A41BFA06715B347DB5736FEE97A0EA0542FC5D75292E7C3413CAF662164D2526C6CD84C43872A348421868CA83417D7A5FF1E7FBBB049F6A552C9C41D9AEE597E23EA61FC981E8A64DF7AF9220A592B2B6218463CF0FB799984C81C838A29F6C28C31A973D73A086814E&h=9718E97374263F4AAAB9DEC4BF486831BD67787B89802668D60C1D080A217741&directdownload=1&f=3346679&d=http://en.zxt2007.com/.../imagetopdf_setup_ad.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=MX&sid=86c7016352deb92da8b8e6523bbb197e&upv=d7e59054fef0ff217d3ffddb1172939c&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAE1A16743FECF3EECEB4DC3D7B3E7AEFB00808D8DF5145BA08457D44610D7CD68DAFAA03723C350B858F6D4E41EFB00FD916009192F9C66C00D40D29B1457284E6808DA324EC953F2F0E960415040A991152E16CCCF6EDDFB7ECDEA96DE07321B24335E675264912B866ADF13E90FE40A6DAC5DAC1701E54926F4DDDE7B88E105977307DB60D49FFBF75418C05E3E6B19&h=2F3D54106F429CF8770AB90FF0D0A8657902EAC3894E7E6BFA6685C2542E190C&directdownload=1&f=3346679&d=http://en.zxt2007.com/.../imagetopdf_setup_ad.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=CO&sid=90d4509cc6cb4bc03c34a5b7acd6759f&upv=a7b0515a861062b7cd6cff434e5e8b1d&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAE1A16743FECF3EECEB4DC3D7B3E7AEFB00808D8DF5145BA08457D44610D7CD68DAFAA03723C350B858F6D4E41EFB00FD916009192F9C66C00D40D29B1457284E6808DA324EC953F2F0E960415040A9919F97C224408DE04CB27BAAF1C74B644275797EABF445DD153D6A01D52E267688F4BDD43B728E415705DA9301E1C41779BAAFA37B014EA432349C8912B7CE9E51&h=5603AFEA03D744606D2D339E243FBD5B2BC35CF1B2CCE84F6AB4C2A812DC10B0&directdownload=1&f=3346679&d=http://en.zxt2007.com/.../imagetopdf_setup_ad.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=MX&sid=bd3442b932c6ea1ba6959ba39c0bdecc&upv=c1a59136b83d2741810a3f64b5a4a84e&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAE1A16743FECF3EECEB4DC3D7B3E7AEFB00808D8DF5145BA08457D44610D7CD68F88C92AFF8A0B797E4E3A0CBA7AA449167894247B3B5DEBCAEF75BF20FADD9AADBDFA8475CEEC15143914966006675F2C1E77FE770E31AC40034C6FD91E0531E5BB3B7C21380A62B4CFAB4ED6C1C4F67A23E6363D7E02D7931DBFF2C007D1EAD6479E40702878DB23B39A4979DA5D7CB&h=E2C50C44B93810420EFA0B7BAE66E092250FC53B226EF4F9906C9FA13BA52B1A&directdownload=1&f=3346679&d=http://en.zxt2007.com/.../imagetopdf_setup_ad.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=CO&sid=94652b193ab0c860a14b7dad73b62cbf&upv=7e329d0a6187489c43e3a446abb3deae&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAE1A16743FECF3EECEB4DC3D7B3E7AEFB00808D8DF5145BA08457D44610D7CD68F55E8E2D3B16AD6025B8679892D1CA3EFF57ABA2748C205ED1B6516FA92E983B1DF829E785D6F20B97E47BABBC4840D9FD260BBA52ED5887516FAC146DC3B00D967F53BE2C3463D9A24D4A880A980FDE2BEA7AD5A4A549490B52A844CEFBC39F7F362D098FBDE6F5AA9B81C34088A716&h=858AD7E08049A075B4CD7111FA014C370EC6EBA5B9791DE1810BAA35534B3B00&directdownload=1&f=3346679&d=http://en.zxt2007.com/.../imagetopdf_setup_ad.exe

Remove imagetopdf_setup_ad.exe - Powered by Reason Core Security