Toucan_3.0.4.paf.exe

Toucan

Rare Ideas, LLC

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from toucan.softonic.com and multiple other hosts.
Publisher:
PortableApps.com  (signed by Rare Ideas, LLC)

Product:
Toucan

Version:
3.0.4.0

MD5:
d0be8adb9cd0d69baf5354feee735ad9

SHA-1:
a1e77b605327a61585be8f2acbc3682ff8e3fa30

SHA-256:
d2c6f212cf5ac7b019d54197e04add13f6a4328e0843d6c80f7419147b5ddb73

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 6:46:54 AM UTC  (today)

File size:
2.9 MB (3,087,560 bytes)

Product version:
3.0.4.0

Copyright:
PortableApps.com Installer Copyright 2007-2010 PortableApps.com.

Trademarks:
PortableApps.com is a registered trademark of Rare Ideas, LLC.

Original file name:
Toucan_3.0.4.paf.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\toucan_3.0.4.paf.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
2/16/2010 1:00:00 AM

Valid to:
2/17/2011 12:59:59 AM

Subject:
CN="Rare Ideas, LLC", O="Rare Ideas, LLC", STREET=PO Box 227, L=New York, S=NY, PostalCode=10009, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
1A3526A1CAB8A8D6926EFF44E133238B

File PE Metadata
Compilation timestamp:
4/10/2010 2:19:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:DLBp5B4anMsMVfMx8+P9+B+clbe2lZO4IP74GbFOlBZU6rZXZsCMWFMoUrYUGfOK:DLT4NsIygB+cNeWA/4NlBZPVuW3UrBGP

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file Toucan_3.0.4.paf.exe has been seen being distributed by the following 8 URLs.

https://toucan.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/trmsvRChbxdrflJq3ZIylWtwaD3oP/HjbttO2 kNPANdj4v0muF9SGy8N1k TRXOXNWpbfXJddyfagLmdcx0CUWYNMP9fEH/9SkcQZMGIkVJ8JfOqAcV8sFx7nEQDk8iF1Bwa7kWnQqT20KDkkvfUhyiOWqOkhH9T/W9ULZxUIZAtFju7ff/M7Mmshkah19nlwy33fH2jy31pbxmzYyflUJZqfhyLG maSM8op3BL/NQJ3TV4GoNUjAsLEKDLx0zvYoeaQwBXMMWuRK7LaCUugznfoFtucRxgRDI2gmzHI5E6vCvjI 3x/jCirQomqSX/U5E56u4WsQEmNN5a6L0YNoFUASHoR7zHLMhiS5FoWsiP/ial9HHRIuj1qarWOik2qvCIhvhUAaDBONpp4yjYb1HW z286KavNS01o7Aq4te1mvx8xTy1yXC0xJxe0jNuQ2xTaH RCYbfqnPHnFqCEAMg/6vo/uwiyL2F8u4gFYhMPz6gjXDhvulPeVpL/FXtmjv0L7enZ8kDE8stzNaFdeIigrcIoeOFnhAsldxrbq3SZNPmGKcadQzxbbGJ VEbUGJOCRZIq6Sk/2Jpn2nbx7AIOde8F/.../GN3IADhTvmnI=

https://toucan.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/trmsvRChbxdrflJq3ZIylWtwaD3oP/HjbttO2 kNPANdj4v0muF9SGy8N1k TRXOXNWpbfXJddyfagLmdcx0CUWYNMP9fEH/9SkcQZMGIkVJ8JfOqAcV8sFx7nEQDk8iF1Bwa7kWnQqT20KDkkvfUhyiOWqOkhH9T/W9ULZxUIZAtFju7ff/M7Mmshkah19nlwy33fH2jy31pbxmzYyflUJZqfhyLG maSM8op3BL/NQJ3TV4GoNUjAsLEKDLx0zvYoeaQwBXMMWuRK7LaCUugzMQm8qooWf4XwWmVRSl7HjHNr01lg8p0Oumb0kc9LdBQonp8o5XtCs32KhUzVDGshdRF3cdyxIekDP/BVEPips96TfJiqgzxuDCWRtojx83w0vhHgjolMW IruqWL6UiQQzosDcOuHT3kEJ2KhOEDPDOxarmATC62z8 I6CQv69QfT2dQ2j2 kI0JUiqzaInwF9Jhhuqp/z0 muKcCePlhQuoDbys6yJ5ERFJVHfh7vjLsYenWsyg8FphACVUfM9CIigrcIoeOFnhAsldxrbq3SZNPmGKcadQzxbbGJ VEbUGJOCRZIq6Sk/2Jpn2nbx7AIOde8F/.../GN3IADhTvmnI=

http://toucan.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/trmsvRChbxdrflJq3ZIylWtwaD3oP/HjbttO2 kNPANdj4v0muF9SGy8N1k TRXOXNWpbfXJddyfagLmdcx0CUWYNMP9fEH/9SkcQZMGIkVJ8JfOqAcV8sFx7nEQDk8iF1Bwa7kWnQqT20KDkkvfUhyiOWqOkhH9T/W9ULZxUIZAtFju7ff/M7Mmshkah19nlwy33fH2jy31pbxmzYyflUJZqfhyLG maSM8op3BL/NQJ3TV4GoNUjAsLEKDLx0zvYoeaQwBXMMWuRK7LaCUugx0FnY5cDxJHOaJxySNKEqNKYKWNsSDR0jJ917CNWT6EtT Qe0Gqw8dGitdW3ba4RWpLdbjafz2hxdlLzm8sLgcPxOKfmwPG6Ub9vnQk3XfnSZoj3iZDWh56sh/ B9YgjxPCxNwRGPg5uaGI4jAZ7Zou5tsB4b0Di2FWtLT6bttibtv7TjKgRGi0GZbKlcrXZpE9cL ZZ1AGa71 c8MkHAItX8Pmt6QUHKYOfT06B3/dedb86xZat1FnwIq4DtJm5iIigrcIoeOFnhAsldxrbq3SZNPmGKcadQzxbbGJ VEbUGJOCRZIq6Sk/2Jpn2nbx7AIOde8F/.../GN3IADhTvmnI=

http://toucan.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/trmsvRChbxdrflJq3ZIylWtwaD3oP/HjbttO2 kNPANdj4v0muF9SGy8N1k TRXOXNWpbfXJddyfagLmdcx0CUWYNMP9fEH/9SkcQZMGIkVJ8JfOqAcV8sFx7nEQDk8iF1Bwa7kWnQqT20KDkkvfUhyiOWqOkhH9T/W9ULZxUIZAtFju7ff/M7Mmshkah19nlwy33fH2jy31pbxmzYyflUJZqfhyLG maSM8op3BL/NQJ3TV4GoNUjAsLEKDLx0zvYoeaQwBXMMWuRK7LaCUugyiHFVBmWL55w9PKpL5tPg1d4UUkuoR1YSMwHQOkd/Tebf2TQsaLfoL93GtttwwDJNirQuWf0 jhi8g5WAStOTcsupCglyXcdnFbdCMulN6AV0pdtgkhEp/8HvfwcqfoF JE1l8WNSSzS8TXJ2kvdgOQXs7J 3lmPLcEsKUmubLWZfSM6y6j2lRM9bIV0xwq3 XBj/z/R9VYIeuBUT/tfZR1KbxLJ9QRTF9TcDdFZCB71RSEDC g5tCMM K4ocByruIigrcIoeOFnhAsldxrbq3SZNPmGKcadQzxbbGJ VEbUGJOCRZIq6Sk/2Jpn2nbx7AIOde8F/.../GN3IADhTvmnI=

http://toucan.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/trmsvRChbxdrflJq3ZIylWtwaD3oP/HjbttO2 kNPANdj4v0muF9SGy8N1k TRXOXNWpbfXJddyfagLmdcx0CUWYNMP9fEH/9SkcQZMGIkVJ8JfOqAcV8sFx7nEQDk8iF1Bwa7kWnQqT20KDkkvfUhyiOWqOkhH9T/W9ULZxUIZAtFju7ff/M7Mmshkah19nlwy33fH2jy31pbxmzYyflUJZqfhyLG maSM8op3BL/NQJ3TV4GoNUjAsLEKDLx0zvYoeaQwBXMMWuRK7LaCUugwHI7nSo4OeJ4wHXat0day7xt7RH59p01GsAfPgZRHLp1vzjabB6spGds/qhn/WX 68pOI6YXYl M4g3bcRnMM0KUYuEJorc6Tbo68HMFvC5gpy7mCLbO4lMfl7Ut2JO1qBF2LOO2obda8S25cT pBBDeL5QWAF6QXSqtpGVqeYt1o3Ny8w5JYRQZUg90W TBOfPGjjF7D6/NYWFXRyLM044etRr4E9KpVkRxWc9BtzUOtqzyld6SZryLk24GGSZXqIigrcIoeOFnhAsldxrbq3SZNPmGKcadQzxbbGJ VEbUGJOCRZIq6Sk/2Jpn2nbx7AIOde8F/.../GN3IADhTvmnI=

Scan Toucan_3.0.4.paf.exe - Powered by Reason Core Security