SmashPdfRdr.exe

SmartShelter

WIBU-SYSTEMS AG

This is a self-extracting archive and installer. The file has been seen being downloaded from www.wibu.com and multiple other hosts.
Publisher:
WIBU Systems AG  (signed by WIBU-SYSTEMS AG)

Product:
SmartShelter

Description:
SmartShelter|PDF Reader Setup

Version:
11.15.0.0

MD5:
391a2cc10a458576ef566a9fe47b36c6

SHA-1:
31f1959f61e1d05deb089839b8dcda659d5d5b2e

SHA-256:
65df7537872a2287855a865b422fb78e213bca9595fe56cb712007cb81ede250

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/6/2024 4:44:22 AM UTC  (today)

File size:
7.1 MB (7,466,032 bytes)

Product version:
11.15.0.0

Copyright:
(c) 2015

Original file name:
SmashPdfRdr.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\smashpdfrdr.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
4/1/2015 3:00:00 AM

Valid to:
7/1/2017 2:59:59 AM

Subject:
CN=WIBU-SYSTEMS AG, O=WIBU-SYSTEMS AG, L=Karlsruhe, S=Baden Wuerttemberg, C=DE

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
2F930689E02D929C085823F12E809E27

File PE Metadata
Compilation timestamp:
9/3/2012 4:51:00 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:5YiKgluee3qDc4loFf8aXTpvQT9qu+sPXz8:4leIquiEeT9q7Ej8

Entry address:
0x3CBD

Entry point:
E8, 1A, 17, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 10, 75, 20, E8, 60, 27, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, E8, 26, 00, 00, 83, C4, 14, 83, C8, FF, E9, A1, 00, 00, 00, 8B, 45, 0C, 56, 8B, 75, 08, 3B, C3, 74, 21, 3B, F3, 75, 1D, E8, 31, 27, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, B9, 26, 00, 00, 83, C4, 14, 83, C8, FF, EB, 74, C7, 45, EC, 42, 00, 00, 00, 89, 75, E8, 89, 75, E0, 3D, FF, FF, FF, 3F, 76, 09, C7, 45, E4, FF, FF, FF...
 
[+]

Code size:
57 KB (58,368 bytes)

The file SmashPdfRdr.exe has been seen being distributed by the following 2 URLs.

https://www.wibu.com/downloads-user-software/file/.../777.html?tx_wibudownloads_downloadlist[directDownload]=1&tx_wibudownloads_downloadlist[useAwsS3]=0&cHash=9f0e9fb86112d6b5dc5c919db1fa776d

Scan SmashPdfRdr.exe - Powered by Reason Core Security