x-dvd-copy-express2.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.xilisoft.com.
MD5:
141744048625a93d54c9dd20e7be2ff5

SHA-1:
42019213da5f721093af7fba8066776a93fcd0d4

SHA-256:
66f20910fe106dbe6478eff6660e7fba4e05336375b6d76425ee138e668bcaab

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 7:54:31 AM UTC  (today)

File size:
21.1 MB (22,104,136 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\x-dvd-copy-express2.exe

File PE Metadata
Compilation timestamp:
10/17/2009 5:19:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
393216:8fUaCqkwEqj9Dty6Hk42pL9pUUMnwVKtZcZMUCDsrZprY2WLIqJxw:8fzCqkwES9DtQDU7wj84lpUjL5w

Entry address:
0x3544

Entry point:
60, 4D, 13, D7, 75, 09, B8, DB, 2B, A1, 92, 43, 0F, AF, ED, 87, C2, 69, C5, DB, E3, D7, 78, 8D, 2D, 27, 56, 08, 79, 8D, 1D, 0D, 48, C4, 0F, EB, 02, 89, F0, 81, E9, 7D, 2C, F5, FF, 01, C7, 89, F0, 0B, F3, 81, E9, 33, 88, 0B, 00, 18, F1, FE, C1, FE, CC, 68, 0D, 3A, 73, 00, 22, F6, 8D, 3D, 6A, 1D, C2, 53, 69, DD, EE, 3F, C2, 86, F3, 05, 94, A1, CE, EC, E8, 38, 00, 00, 00, 81, FD, 55, B2, 00, 00, 78, 08, 81, CB, 43, A4, 6A, 77, 85, C7, F7, C3, F7, AF, 1E, 2D, 0F, BE, DC, 78, 08, 22, FE, 80, D5, FD, 0F, BE, C2...
 
[+]

Entropy:
7.9996  (probably packed)

Code size:
24.5 KB (25,088 bytes)

The file x-dvd-copy-express2.exe has been seen being distributed by the following URL.

Scan x-dvd-copy-express2.exe - Powered by Reason Core Security