nis_21.1.0.18_symtb_tmd_mrftt_820_10131.exe

Norton Internet Security

Symantec Corporation

This is a setup program which is used to install the application. The file has been seen being downloaded from norton-internet-security.ro.softonic.com and multiple other hosts.
Publisher:
Symantec Corporation  (signed and verified)

Product:
Norton Internet Security

Version:
21.1.0.18

MD5:
0bf5d87914c1d6ae961e57d62afd87ea

SHA-1:
ae62fc243c63cd6a3d0ddeb2657fd38b17c02500

SHA-256:
1231aac7064fdf5e2ae1616ee9db6c5e6cdd26d95c40c0b9d327751ddd5487ce

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 2:00:52 AM UTC  (today)

File size:
212.8 MB (223,165,336 bytes)

Product version:
21.1.0.18

Copyright:
Copyright © 2013 Symantec Corporation. All rights reserved.

Original file name:
NIS_TW.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\nis_21.1.0.18_symtb_tmd_mrftt_820_10131.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/8/2010 4:00:00 AM

Valid to:
11/24/2013 3:59:59 AM

Subject:
CN=Symantec Corporation, OU=Symantec Research Labs, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Symantec Corporation, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
66660552D465B31F429F7527EA6A93BF

File PE Metadata
Compilation timestamp:
10/8/2013 8:51:22 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3145728:s/CQ2Gt6tgghd10SaxES8e84+CnV18t/OQTPgyvD8nasxgCzQ8qHeEM0sTmQ5mjN:s/9G1078EV18tRTxvwnaMQ8qWIjDdbjb

Entry address:
0x5377A

Entry point:
E8, 6E, 72, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, FF, 75, 08, E8, 20, A4, 01, 00, 59, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81, F9, 80, 00, 00, 00, 72, 1C, 83, 3D, 14, F2, 4B, 00, 00, 74, 13, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 05, E9, 2C, 67, 00, 00, F7, C7, 03, 00, 00, 00, 75, 14, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 29, F3, A5, FF...
 
[+]

Code size:
561 KB (574,464 bytes)

The file nis_21.1.0.18_symtb_tmd_mrftt_820_10131.exe has been seen being distributed by the following 26 URLs.

http://norton-internet-security.ro.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-flqSJoKSnkZY=

https://dw.uptodown.com/dwn/ggFLKXpSu_uKQ1MjzKXyy8Yl7uSBWngd5BFShHeotjmsKb2spnAr5zoKv0ldNVgGG18jkN6k7aaTWxRnmYDfM0Fg2HlMKHPYHe-mEctGHXTK7Bleo_ifObVHeEQsdga_/YaUxJ7DQP3OXCOpY12t0exZBH3cNa7DR9dPf_ftjnX2XJDCiDHcMRlgfozujVqrZv4Mduj_bL9L3QSmC8NexmDmhOu4s_iq7Ga3JmodTZRqlR-1tCqf7bUhlA00F8-eF/3WIOOhx3Q80tmZdZ-_4TMUuXXoRi-DQ4L2hy-pOgjtud6ZK5MSdq0Ob3QfQOH-kbPWDaPH9hJRXjmRoFM4ZUczndQhxpOA9E0cD37KGOOQ91RzDXFN4A2Pu3Zg-xmBPW/.../

http://gsf-cf.softonic.com/ae6/2fc/.../file?SD_used=0&channel=WEB&fdh=no&id_file=9907&instance=softonic_en&type=PROGRAM&Expires=1430443849&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=aqHZRa6bCbeUqmPGmZbo2uU9ov536AFSAL-NQzL6XCHFVNWMJygkQt0M5NKbKWqFyDY5OKkLEXgWCjUW~phj9nkcUOvoSXtG~wg2bJe7W2k3zXpjQKYodtGiPHfgvcxYzM10uTTiIJ6mj32K5n0LZiSn1GePEJ0ep04veeZiT88_&filename=NIS_21-1-0-18_SYMTB_TMD_MRFTT_820_10131-SOFTONIC.exe

http://gsf-cf.softonic.com//ae6/2fc/.../file?id_file=9907&channel=WEB&instance=softonic_br&type=PROGRAM&fdh=no&SD_used=0&Expires=1408872799&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=FKL41s-qbjpCH~E0DLs8huzUztfQ7cIkycAZORbOTiTSHg6QPDRdgHpJ0SB4dJAIE4P1Sl4dRy~TzkmOj4ofXochvOV~wouDier4pY8ocetk7s~8mQ9iJy~7t8qoj~Z8Nsz6W-2cEyLDxyLDBNIU1AZtnXRpFogbN1Hh48emRBU_&filename=NIS_21-1-0-18_SYMTB_TMD_MRFTT_820_10131-SOFTONIC.exe

http://gsf-cf.softonic.com/ae6/2fc/.../file?SD_used=0&channel=WEB&fdh=no&id_file=9907&instance=softonic_es&type=PROGRAM&Expires=1418498040&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=Kynor1efA2BhjWZLRwCJGo7zCck9U0cUGhSKdLOP7znPazd8EZLfsoCnkqcy0MI0Ic2YZCxCHQZgtEuwtNg54bSK70mZeXureev-gVP52zpnp69VXYoK3m3XsxhAGIarE4MzP1rhCKaO-lEiMq4EgbonceBHGVZdeaLialg6qMI_&filename=NIS_21-1-0-18_SYMTB_TMD_MRFTT_820_10131-SOFTONIC.exe

http://gsf-cf.softonic.com//ae6/2fc/.../file?id_file=9907&channel=WEB&instance=softonic_es&type=PROGRAM&fdh=no&SD_used=0&Expires=1408184186&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=dWIYC9Xx4AmHDHpz4EsyW-AA48Ir1EUJwlbBGFxjuZKzuHIKfCRSBWNA9lWus7i7Pa8sH8IZT7jho0qKDBWtwhASfDP7X0JYScO3GrpQ8kiODDWSbCVAR02mo2gNDJo2mMfbJRBLnPIxPxNBrvnuha5s4W8utN4uhUpE32lv1Zk_&filename=NIS_21-1-0-18_SYMTB_TMD_MRFTT_820_10131-SOFTONIC.exe

https://dw.uptodown.com/dwn/GjGPouQz5lk6U920yUQBkWtrDz-w46-XdpoH6O3fu4w1WpD-NZ3wzL6JwxkF_j3jdHu1VH1kPDONbZD2AKEjlqGtn_Hojc-rLl2cFjilKsaVkXIRxzLkq6JSguExsXRO/dASEj5RLuiNrksdVZa5JH86yptusxo-jrufcMYxmP1DkH1ZOiuebn8E8RCTDpyqyxftvCz207GY_9I5PqelVME9v1wYPvz2KBUA6PS_AKqIur9q_3VOZMYvhWWS1qkc1/CL9OfSQSQpO8Nf2ntBIMCTWvnBDuxTehJVWWHCESUglhw7XNkdcufsL9CsfrtlRu3ZXt6V1cv5jGF0lFjH2DxnXoYL5DWAgqtTVq7M8csV_dW2vp4fgUhRs84WuCVI5b/.../

http://gsf-cf.softonic.com/ae6/2fc/.../file?SD_used=0&channel=WEB&fdh=no&id_file=9907&instance=softonic_es&type=PROGRAM&Expires=1426822180&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=aGNLpPlVewLC9MxS5ld51bODug1EceRUJffBeWastcuZ6r9uU67rU-U7i7vXrbuc6IqhH3V4UT2VKkYb50I7ATr38GF49Nwcpl-EirkGo~4HzFD45P6twzjIt5GZwdsyKg6SY16lVzvnvrXYCGYRydKUZzCdeyWxOUIJYFqg~uc_&filename=NIS_21-1-0-18_SYMTB_TMD_MRFTT_820_10131-SOFTONIC.exe

http://gsf-cf.softonic.com//ae6/2fc/.../file?id_file=9907&channel=WEB&instance=softonic_it&type=PROGRAM&fdh=no&SD_used=0&Expires=1399154264&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=hLu5-z5LJwDbOXFYfW2rp7oyV3qlHUNcoVbJb9pX2Nx6TOkRMSqINLGZZBlZ6rrD7amPdyrHMKvfRLpc4aJKMQnEhvh19BD0mIrUoKYUtLLJU-uYgUIGcimkX26ycYfnGk05Ln~LU3ONEVfY6mzAOQABako0F7Z~H3QCSwKZicg_&filename=NIS_21-1-0-18_SYMTB_TMD_MRFTT_820_10131-SOFTONIC.exe