install_sleekbill_india.exe

Intelligent IT

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from en.softonic.com and multiple other hosts.
Publisher:
Intelligent IT  (signed and verified)

MD5:
c2b8c24978fc2963c703c64c214855e9

SHA-1:
c91b14a3e6e6e6b14eb003372192c9413742e307

SHA-256:
e357782a46982eeef4c54eec3c483bc5c1647fe2dbfb767e19768fda1ab058c9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/15/2025 6:41:08 PM UTC  (today)

File size:
37.9 MB (39,770,600 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\install_sleekbill_india.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/3/2015 5:30:00 AM

Valid to:
2/26/2016 5:29:59 AM

Subject:
CN=Intelligent IT, O=Intelligent IT, L=Sibiu, S=Sibiu, C=RO

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5E0E3E84806B80570796EA85A07DB1DB

File PE Metadata
Compilation timestamp:
4/10/2010 5:49:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:8ogpISwT0QKucIn3lh/VxP58XEGDmqTtaOMlJt2R8fKuX2pS4Rzz0/WLN:8kSwTKxIn3lh/zh6y6tXMlX2SSwcN

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
8.0000

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file install_sleekbill_india.exe has been seen being distributed by the following 19 URLs.

http://en.softonic.com/sads/tracker.php?ev=c&co=IN&sid=3fcf6e6630ef0ea324f570acbf6de45e&upv=114f3efdc973930ea91e5afd6caa08e6&z=list&sk=1291&abp=0&params=F39B2A32BFC101987B1458170C278E036C6ABD86CA63A494CC3E4EB139EFEADD9E5C14A61285DF34CE5D8E6E3C67676F514E0E324DDB854C89C963F87F9D28FAC6515B55C62124B507207EE9FCC11E7184F4BED325615A1B6331CFC3B742D033C213F0BEE512F264AB47A47509323E2DB963145C75F2A4187DA64DCA411C522D941940DCF0C839E0BBE08324EFCE4D9F5D34A4209AC54E5F71F2A875E36027C4BD3C8DFC53125EE1FD64DF1CFB598177&h=764B27D4A42083E01E0DD1EBEF34D2762ADD5E122348BDAE5AB341B5A7CC2680&directdownload=1&f=69700502&d=https://www.billingsoftware.in/Installers/.../Install_SleekBill_India.exe

http://en.softonic.com/sads/tracker.php?ev=c&co=IN&sid=d1ffcdc84dfd4259a30b534c98525eb9&upv=8b2bd76941e6533be5f9a4d9e5daabb3&z=results&sk=0&abp=1&params=F39B2A32BFC101987B1458170C278E036C6ABD86CA63A494CC3E4EB139EFEADD232E6708269445399D7852BF65670808DA565EF53F77D3C67504FA5B54985F1733EED6237801CFC3EEA7CFBDCFC574C4448009143208D7473C6E59DC57AEB826DCADC316720529801B219504AB9090768F85868AA8477B247F89FCB1718645C657DD6DC958714CC8E74FB6EBF4707DBB0F0978DB1D5ED908FFE8F0C64A525515DBAFFAED7D6316EAED1D0D0B7A0E7360&h=3496DCE4BE8D3FC18BD67BFBD0C623A3E9A0C603C25BA9AA222F78245E3AD885&directdownload=1&f=69700502&d=https://www.billingsoftware.in/Installers/.../Install_SleekBill_India.exe

http://en.softonic.com/sads/tracker.php?ev=c&co=IN&sid=af5d7f5053845cef08c236c646b71269&upv=2a20dffd00213bef99e73112e492b3ce&z=download-cpd&sk=1317&abp=0&params=F39B2A32BFC101987B1458170C278E036C6ABD86CA63A494CC3E4EB139EFEADD9E5C14A61285DF34CE5D8E6E3C67676F514E0E324DDB854C89C963F87F9D28FAB74807A9FAE4653487CFC586750AF388A6E8892B8D19BF7CDD1309B516BE1D6922E4980F466B6086B8ECF1979FC1C55EE514587170CC846D7927D365CB32BBF193F0BFFCCE2B44B2B6650F47558201D7871AE5C5A3B3C55599748A8C2411695B3F2522453C0E36D2D6506A52AAFC92B2&h=A66F2C67FB97E1298E85B19E30A2C312D1BFCCEBB688D74107711FD352CE5CFE&directdownload=1&f=69700502&d=https://www.billingsoftware.in/Installers/.../Install_SleekBill_India.exe

Scan install_sleekbill_india.exe - Powered by Reason Core Security