setuppoker_afdbe0.exe

Playtech Software Installer

PLAYTECH LIMITED

This is a self-extracting archive and installer. The file has been seen being downloaded from banner.offsidebet.com.
Publisher:
Playtech  (signed by PLAYTECH LIMITED)

Product:
Playtech Software Installer

Description:
Offsidepoker

Version:
9.4.20.0

MD5:
eb622cd350193d251d9a97deb008bcdf

SHA-1:
487625e11e4072890d1676609c4726cae8b64882

Scanner detections:
1 / 68

Status:
Inconclusive  (probably just a false positive detection)

Analysis date:
2/26/2025 1:54:21 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.PLAYTECH.Installer
16.4.10.9

File size:
238.3 KB (243,968 bytes)

Product version:
9.4.20.0

Copyright:
Copyright (C) 2001-2009 Playtech

Original file name:
CasinoDownloader2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setuppoker_afdbe0.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/13/2009 2:00:00 AM

Valid to:
3/13/2012 1:59:59 AM

Subject:
CN=PLAYTECH LIMITED, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PLAYTECH LIMITED, L=Douglas, S=Isle of Man, C=IM

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
19A52BD0FFBF33D2D2ED2030B214DBA6

File PE Metadata
Compilation timestamp:
9/2/2009 2:54:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:86ZmkWkr9eZX7RwlH2/8UcR10g77qnrhcvFHrqaLtg:ABS9eZX9w2/8UcH0lheF3L+

Entry address:
0x2DDDB

Entry point:
B8, 88, 90, 4D, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, C2, 9C, E1, 0F, 55, 5B, D7, 8C, 9D, B9, CA, A7, 40, E8, 52, 84, B2, FC, 18, 61, B3, BA, 87, EA, 6E, 0F, 76, 6C, 16, 5C, 26, 4E, 88, 91, 8A, DE, 10, 30, 5E, 03, D7, 89, 6D, ED, 88, C1, D1, 36, 39, 9D, 3C, B3, 0A, 95, 4F, 59, EE, 09, D1, F7, 87, E6, 28, 0E, 8D, 8D, 20, 23, 6B, 23, 3C, 6A, 18, 74, 16, 73, 1A, A9, F2, DD, CB, 56, CE, 79, 6F, 9F, 96, 64, A7, F3, 11, D6, D1...
 
[+]

Packer / compiler:
PECompact v2

Code size:
260 KB (266,240 bytes)

The file setuppoker_afdbe0.exe has been seen being distributed by the following URL.

Scan setuppoker_afdbe0.exe - Powered by Reason Core Security