360is_softonic_4.9.0.4900.exe

360 Internet Security

QIHU 360 SOFTWARE CO. LIMITED

This is a setup program which is used to install the application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Qihu 360 Software Co., Ltd.  (signed by QIHU 360 SOFTWARE CO. LIMITED)

Product:
360 Internet Security

Version:
4,9,0,4900

MD5:
4c44c5148128fc528afe2de4838d7062

SHA-1:
0b04019a4c0c9d1d74b37f8d6cb0d41ec59002c4

SHA-256:
18f45f6fb4b48d3ac21cd9ed8a3e48ee14f55e76cc03dcec062072614ef21edf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 1:56:10 PM UTC  (today)

File size:
30 MB (31,451,128 bytes)

Product version:
4,9,0,4900

Copyright:
(C) 2013 Qihu 360 Software Co., Ltd.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
Symantec Corporation

Valid from:
5/20/2013 5:00:00 PM

Valid to:
5/20/2016 4:59:59 PM

Subject:
CN=QIHU 360 SOFTWARE CO. LIMITED, O=QIHU 360 SOFTWARE CO. LIMITED, L=Hong Kong, S=Hong Kong, C=HK, SERIALNUMBER=1848744, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=HK

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
541FDA68B5E95006F2FEC51BEA326365

File PE Metadata
Compilation timestamp:
1/9/2014 3:40:18 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:M7vtDHAUjlHmM7EXk0BORFndnu3w4v/bI7qTge8WxS:M7VDf1PFl8TFTg6S

Entry address:
0x2D99B

Entry point:
E8, FC, FF, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 83, 3D, 08, 49, 49, 00, 00, 0F, 84, 39, 03, 01, 00, 83, EC, 08, 0F, AE, 5C, 24, 04, 8B, 44, 24, 04, 25, 80, 1F, 00, 00, 3D, 80, 1F, 00, 00, 75, 0F, D9, 3C, 24, 66, 8B, 04, 24, 66, 83, E0, 7F, 66, 83, F8, 7F, 8D, 64, 24, 08, 0F, 85, 08, 03, 01, 00, EB, 00, F3, 0F, 7E, 44, 24, 04, 66, 0F, 28, 15, 40, 8D, 47, 00, 66, 0F, 28, C8, 66, 0F, 28, F8, 66, 0F, 73, D0, 34, 66, 0F, 7E, C0, 66, 0F, 54, 05, 60, 8D, 47, 00, 66, 0F, FA, D0...
 
[+]

Entropy:
7.9920  (probably packed)

Code size:
459 KB (470,016 bytes)

The file 360is_softonic_4.9.0.4900.exe has been seen being distributed by the following 7 URLs.

http://gsf-cf.softonic.com/0b0/401/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69663142&instance=softonic_it&type=PROGRAM&Expires=1427076172&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=UQlwccS2uo~SWPjzMX62IsGX8xeSfVxQGnUeDL9GrxWPLzuh1fU2zSaQ1nTjoUGxATrzQKcqHEJ~A61KRrTayWmobOKUy9Of1Lq1FUcVoMjdVoRCuNmxwkDbYCFpy0epoLFNmAFSlErGAUKXg4brrN7qv5NOYAgHj3FZHsaJU1c_&filename=360is_softonic_4.9.0.4900.exe

http://gsf-cf.softonic.com/0b0/401/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69663142&instance=softonic_fr&type=PROGRAM&Expires=1428876979&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=iTc4d6yS8Xw4jUBO6x4rrmzN6AmQaL7s~56EZLAQy066D5wm5OyNLGGFMZLMA7pNgrGoHxjpFDhMiRAz04E5Xfaq52LdjaNue-psG5lYOqMymcK~IL4wfe~-Vit1yx1V6-UeOCMn0~zWceQw1Und~~wXXadWaAzkEF-nRK1CV~A_&filename=360is_softonic_4.9.0.4900.exe

http://gsf-cf.softonic.com/0b0/401/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69663142&instance=softonic_en&type=PROGRAM&Expires=1423528552&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=NuAi8XPt4N11f5m3QQ4tEuv6vkuERk2Hx6JEwy~fhbeLJmdGMHo5hlvv9iq-m1P4RIEy41zwDafwq86wn6lepsZf0I1t-aBH~f18gv~FMMFpMSisVApngL4V31sQERil1XOZ6daaXobpJEH-~6wlas7LdE7cMSNXXbe~Myv0JOw_&filename=360is_softonic_4.9.0.4900.exe

Scan 360is_softonic_4.9.0.4900.exe - Powered by Reason Core Security