ptu201d_tmp.exe

Playtech Software Installer

PLAYTECH LIMITED

This is a setup and installation application. The file has been seen being downloaded from banner.casino.paddypower.it.
Publisher:
Playtech  (signed by PLAYTECH LIMITED)

Product:
Playtech Software Installer

Description:
Paddy Power Casinò

Version:
13.2.11.0

MD5:
13478c3d90d583f9b98be78b7a77b551

SHA-1:
6eb0a7e5883c76a4cd8413904a9f6cfc9fe4bec4

SHA-256:
988687bfc083c32b45c1972e8bce9f40647bf0483db679514af20c41de06ef36

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 2:54:41 AM UTC  (today)

File size:
226.1 KB (231,536 bytes)

Product version:
13.2.11.0

Copyright:
Copyright (C) 2001-2009 Playtech

Original file name:
CasinoDownloader2.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\ptu201d_tmp.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/4/2015 1:00:00 AM

Valid to:
4/3/2018 1:59:59 AM

Subject:
CN=PLAYTECH LIMITED, O=PLAYTECH LIMITED, L=Douglas, S=Isle of Man, C=IM

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
41DE65AB6CE64F53DF33BDC37E67E284

File PE Metadata
Compilation timestamp:
1/17/2014 11:14:13 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:6Cv889gvgQ33+UiKRXuJ1QDLLu1mgG9n3N:Jv/gg6zhXiQDfwmgc3N

Entry address:
0x1000

Entry point:
B8, C0, EB, 52, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 73, 7C, 8E, F6, 11, BD, 32, 60, DD, 0B, 00, 43, A6, 07, C7, 67, 99, 75, A2, 41, 2F, 08, FC, 27, 60, F5, 7C, 5E, 94, B8, 93, 9D, F6, DB, 7D, 06, FA, D2, 25, 92, 44, 4A, FD, 43, 34, F5, F5, 60, DB, B6, B1, 4C, 41, 6D, B0, CF, 72, AE, 63, 94, 17, DE, 57, 19, E8, A0, 1B, 38, 79, 00, 60, F9, 79, 9B, BF, A3, D4, AC, 07, E9, E9, 68, 12, DB, 9F, 35, 73, DF, 75, E2, 06, 5D, 48...
 
[+]

Packer / compiler:
PECompact v2

Code size:
338 KB (346,112 bytes)

The file ptu201d_tmp.exe has been seen being distributed by the following URL.

Scan ptu201d_tmp.exe - Powered by Reason Core Security