nitropdf.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from imgt.taimienphi.vn.
MD5:
86556d2ef73c3ffef540e58995f7327f

SHA-1:
1de4983c3c64cb9de6b7a83b9e7865ca5106b122

SHA-256:
64013294bc9515e590dd2f825bdd38356ca286d4b9c190909d6f911b07179104

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:43:04 AM UTC  (today)

File size:
30.2 KB (30,878 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\nitro pdf\professional\nitropdf.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
768:zCZF0tPdX1OdSJJ3E32C+nPkgUGLy2e3GUMnYigT:uZetR3EGtcjtqc

Entry point:
47, 49, 46, 38, 39, 61, 75, 01, 2C, 01, D5, FF, 00, E1, D4, 90, 47, C9, FA, 07, ED, ED, 48, 8F, AC, BA, AA, 74, D0, C5, 89, F8, C9, C9, E9, 3A, 07, EF, BD, A5, A3, 9B, 9C, 16, 97, 98, 52, 2F, 04, 15, 0E, 0E, 90, 50, 04, 35, 17, 13, 23, 69, 28, 02, F8, 0B, F8, E5, D5, F8, D7, B1, 0D, A4, 15, 4E, D7, FA, 3E, 56, 58, 4E, 41, 31, EA, E1, 9C, 5A, 53, 4C, 70, 65, 57, 78, 65, 18, 39, 35, 38, 2C, 92, 2C, 90, 7D, 63, F8, ED, 9D, 00, B5, 0C, A3, 8F, 75, 29, 25, 28, F8, 00, 4E, 20, 5F, 65, 42, 6C, 7E, 9E, 8E, 39, 7A...
 
[+]

Entropy:
7.9199  (probably packed)

The file nitropdf.exe has been seen being distributed by the following URL.

Scan nitropdf.exe - Powered by Reason Core Security