ntrck_sw60_2397.exe

Windows Installer Internet Download Bootstrap

Flavio Antonioli

This is a self-extracting archive and installer. The file has been seen being downloaded from download.ntrack.com.
Publisher:
Microsoft Corporation  (signed by Flavio Antonioli)

Product:
Microsoft® Windows® Operating System

Description:
Windows® Installer Internet Download Bootstrap

Version:
5.2.3668.0

MD5:
3c092824c2e56b2e3628ce47aafc173c

SHA-1:
952932e179e8e8dd2eba48cdbb37cfac9c5897e2

SHA-256:
fa6833ce11f2a1e407ee7bbbde1336ce9b6c2086aa1f8b693315cbe7890b7891

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
2/26/2025 2:03:04 PM UTC  (today)

File size:
15.7 MB (16,424,128 bytes)

Product version:
5.2.3668.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ntrck_sw60_2397.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
12/16/2007 6:00:00 PM

Valid to:
3/1/2009 5:59:59 PM

Subject:
CN=Flavio Antonioli, OU=SVILUPPO SICURO DELL'APPLICAZIONE, O=Flavio Antonioli, L=Rome, S=RM, C=IT

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
6B2F19CC7ACEA53EFA82928FAD025327

File PE Metadata
Compilation timestamp:
9/30/2008 3:35:27 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xB202

Entry point:
E8, 75, 4A, 00, 00, E9, 78, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 74, AA, 41, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 74, AA, 41, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F...
 
[+]

Entropy:
7.9793  (probably packed)

Code size:
77 KB (78,848 bytes)

The file ntrck_sw60_2397.exe has been seen being distributed by the following URL.

http://download.ntrack.com/.../ntrck_sw60_2397.exe

Scan ntrck_sw60_2397.exe - Powered by Reason Core Security