× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: ec08de633fa4483348cbf9c1484757fa8ad6b8bb924868b28c63abc899ff095e
File name: PdfToWordConverter_dldportals.EXE
Detection ratio: 11 / 61
Analysis date: 2017-06-02 06:35:40 UTC ( 1 year, 8 months ago ) View latest
Antivirus Result Update
AegisLab Troj.Startpage.Skdd!c 20170602
Avast Win32:Malware-gen 20170602
Avira (no cloud) TR/StartPage.skdd 20170601
Bkav W32.Clodb29.Trojan.c9a9 20170601
DrWeb Adware.Siggen.19046 20170602
Ikarus Trojan.StartPage 20170601
McAfee Artemis!FD755F0AE1EA 20170602
McAfee-GW-Edition Artemis 20170602
Symantec Trojan.Gen.2 20170602
Webroot W32.Malware.Gen 20170602
Yandex Trojan.StartPage!SfQuo36KWpg 20170601
Ad-Aware 20170602
AhnLab-V3 20170602
Alibaba 20170602
ALYac 20170602
Arcabit 20170602
AVG 20170602
AVware 20170602
Baidu 20170601
BitDefender 20170602
CAT-QuickHeal 20170602
ClamAV 20170602
CMC 20170602
Comodo 20170602
CrowdStrike Falcon (ML) 20170420
Cyren 20170602
Emsisoft 20170602
Endgame 20170515
ESET-NOD32 20170602
F-Prot 20170602
F-Secure 20170602
Fortinet 20170602
GData 20170602
Sophos ML 20170519
Jiangmin 20170602
K7AntiVirus 20170602
K7GW 20170602
Kaspersky 20170602
Kingsoft 20170602
Malwarebytes 20170602
Microsoft 20170602
eScan 20170602
NANO-Antivirus 20170602
nProtect 20170602
Palo Alto Networks (Known Signatures) 20170602
Panda 20170601
Qihoo-360 20170602
Rising None
SentinelOne (Static ML) 20170516
Sophos AV 20170602
SUPERAntiSpyware 20170602
Symantec Mobile Insight 20170601
Tencent 20170602
TheHacker 20170528
TotalDefense 20170602
TrendMicro 20170602
TrendMicro-HouseCall 20170602
Trustlook 20170602
VBA32 20170601
VIPRE 20170602
ViRobot 20170602
WhiteArmor 20170601
Zillya 20170601
ZoneAlarm by Check Point 20170602
Zoner 20170602
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
PDF-File

File version 3.0.0.0
Description PDF to MS Word document converter.
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2007-11-20 21:12:45
Entry Point 0x000029AA
Number of sections 4
PE sections
Overlays
MD5 3c6448c51cf12d1c794b32b0e8db11b2
File type data
Offset 25088
Size 26269247
Entropy 8.00
PE imports
AdjustTokenPrivileges
LookupPrivilegeValueA
OpenProcessToken
GetDeviceCaps
SelectPalette
SetBkMode
CreateFontA
CreatePalette
GetStockObject
PatBlt
TextOutA
CreateSolidBrush
SelectObject
DeleteObject
RealizePalette
SetTextColor
StretchDIBits
GetLastError
lstrlenA
GlobalFree
FreeLibrary
ExitProcess
GlobalUnlock
GetVersionExA
GetModuleFileNameA
LoadLibraryA
WinExec
OpenFile
GetCurrentProcess
_lwrite
lstrcatA
GetWindowsDirectoryA
SetErrorMode
_llseek
GetCommandLineA
GetProcAddress
_lread
_lcreat
GetTempPathA
GetModuleHandleA
lstrcpyA
_lopen
_lclose
MulDiv
GetTempFileNameA
GlobalLock
LocalFree
GlobalAlloc
FormatMessageA
wsprintfA
CreateWindowExA
LoadCursorA
LoadIconA
DrawTextA
UpdateWindow
EndPaint
BeginPaint
GetClientRect
SendMessageA
MessageBoxA
SetTimer
GetDC
ReleaseDC
PostQuitMessage
DefWindowProcA
ShowWindow
RegisterClassA
ExitWindowsEx
SetWindowPos
InvalidateRect
Number of PE resources by type
RT_ICON 6
RT_GROUP_ICON 1
RT_VERSION 1
RT_MANIFEST 1
Number of PE resources by language
ENGLISH US 8
NEUTRAL 1
PE resources
ExifTool file metadata
UninitializedDataSize
0

LinkerVersion
7.1

ImageVersion
4.0

FileVersionNumber
3.0.0.0

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

FileDescription
PDF to MS Word document converter.

ImageFileCharacteristics
No relocs, Executable, No line numbers, No symbols, 32-bit

CharacterSet
Windows, Latin1

InitializedDataSize
15872

EntryPoint
0x29aa

MIMEType
application/octet-stream

Subsystem
Windows GUI

FileVersion
3.0.0.0

TimeStamp
2007:11:20 22:12:45+01:00

FileType
Win32 EXE

PEType
PE32

SubsystemVersion
4.0

OSVersion
4.0

FileOS
Windows 16-bit

LegalCopyright
PDF-File

MachineType
Intel 386 or later, and compatibles

CompanyName
PDF-File

CodeSize
8192

FileSubtype
0

ProductVersionNumber
10.3.0.0

Warning
Possibly corrupt Version resource

FileTypeExtension
exe

ObjectFileType
Executable application

File identification
MD5 fd755f0ae1eadddbb62b093a27ba8814
SHA1 4b77676d451059d93a53c5ea7cdaa9e466366fd7
SHA256 ec08de633fa4483348cbf9c1484757fa8ad6b8bb924868b28c63abc899ff095e
ssdeep
393216:FeOnTzSH89QlAAaQ0NKa47eeWV0ClQ3T9gpcsXN15GL0nLi2vd8RQ0wpGL:FZTC8d7kameeWVjlip4csXNOLILi2Dpk

authentihash 14c4a4081ada2254e36a1de10b92c3120ae36b12fab5e0b0cf3cff4af7f4e700
imphash 1b1f8bafc7e8e1dafb58725e16275805
File size 25.1 MB ( 26294335 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable MS Visual C++ (generic) (64.5%)
Win32 Dynamic Link Library (generic) (13.6%)
Win32 Executable (generic) (9.3%)
OS/2 Executable (generic) (4.1%)
Generic Win/DOS Executable (4.1%)
Tags
peexe overlay

VirusTotal metadata
First submission 2016-04-07 18:38:31 UTC ( 2 years, 10 months ago )
Last submission 2018-05-23 01:02:18 UTC ( 9 months ago )
File names PdfToWordConverter_dldportals.EXE
831119
EC08DE633FA4483348CBF9C1484757FA8AD6B8BB924868B28C63ABC899FF095E.exe
PdfToWordConverter.EXE
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!