setupcasino.exe

Playtech Software Installer

PLAYTECH LIMITED

This is a self-extracting archive and installer. This is the uninstaller utility registered in the Windows Control Panel for the program 12Win. The file has been seen being downloaded from banner.otwin12.com and multiple other hosts.
Publisher:
Playtech  (signed by PLAYTECH LIMITED)

Product:
Playtech Software Installer

Description:
12Win

Version:
13.2.11.0

MD5:
e7aeae67276ec555100520f80c0ea6bd

SHA-1:
05b924d7510de0621716c19fb5c12f934bf1cd56

SHA-256:
86f493385c210b06ac4ce3e8f8cbbf568615d071fdcb9dde25a493b16e914ea6

Scanner detections:
1 / 68

Status:
Inconclusive  (probably just a false positive detection)

Analysis date:
12/28/2024 10:26:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.PLAYTECH
15.3.18.1

File size:
287.7 KB (294,560 bytes)

Product version:
13.2.11.0

Copyright:
Copyright (C) 2001-2009 Playtech

Original file name:
CasinoDownloader2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setupcasino.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/23/2012 8:00:00 AM

Valid to:
3/13/2015 7:59:59 AM

Subject:
CN=PLAYTECH LIMITED, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PLAYTECH LIMITED, L=Douglas, S=Isle of Man, C=IM

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
08E8E108CB58477BBE7872C837D9D556

File PE Metadata
Compilation timestamp:
1/17/2014 6:14:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:JCv889gvgQ33+UiKRXuJ1QDLLukTyD3X8fpYnNkmcef4aaaaX1hn:0v/gg6zhXiQDfHyOpYNkmcsoDn

Entry address:
0x3533C

Entry point:
B8, 54, A4, 54, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 1D, 53, 9B, C3, 5E, 77, 18, 99, 6F, 7C, 77, A1, 65, F4, AF, FF, 6C, 10, 43, 4E, A0, 7F, 17, 37, 63, 76, 03, 95, ED, 40, BA, 09, 1C, 05, C9, 1D, CB, 56, 33, F7, 40, 63, 7E, F8, B4, 54, 4C, 12, 51, FB, A8, 78, 2A, 08, 2D, 3C, AC, 43, 89, DB, 9E, 8E, 30, 2B, 04, 00, 2F, 16, 3C, 23, C0, 33, EE, 1B, 5D, D4, 56, 8A, AB, 55, 8B, FF, 13, 3C, CD, 6F, C5, 97, 49, 32, 07, 0B, 74...
 
[+]

Entropy:
7.8310

Packer / compiler:
PECompact v2

Code size:
338 KB (346,112 bytes)

Program Uninstaller
Program name:
12Win

Uninstall string:
"C:\Casino\12Win\_SetupCasino.exe" /uninstall


The file setupcasino.exe has been seen being distributed by the following 2 URLs.

Scan setupcasino.exe - Powered by Reason Core Security