7e382dec_stp.exe

Final Video Downloader

Bitberry Software

The application 7e382dec_stp.exe, “Final Video Downloader - Fastest YouTube downloader ” by Bitberry Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.sharepresentcentral.com and multiple other hosts.
Publisher:
Bitberry Software   (signed by Bitberry Software)

Product:
Final Video Downloader

Description:
Final Video Downloader - Fastest YouTube downloader

Version:
2016.16.5.16

MD5:
f1591cec0ef3dff4f4d00d318786fcd6

SHA-1:
403eda58776243051dcdbe710e5573cb6da52ffd

SHA-256:
0f289526ad5947acb82010af3b1599302c740221f1eb4df93a0e20565d3b7939

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 4:58:37 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bitberry.Installer (M)
16.5.20.11

File size:
13.7 MB (14,372,072 bytes)

Product version:
2016

Copyright:
Copyright © 2009-2016 Bitberry Software

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\7e382dec_stp.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/13/2015 5:30:00 AM

Valid to:
3/13/2017 5:29:59 AM

Subject:
CN=Bitberry Software, O=Bitberry Software, L=Holbaek, S=n/a, C=DK

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2B45F5EACFCCD01402902F5B86CE6120

File PE Metadata
Compilation timestamp:
7/9/2014 1:28:13 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:kq1/9QnsrjWddyPQpl6V3yPQ06Wm1ZSD7:Ll9QnsLOk3yPQnfq7

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9990

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file 7e382dec_stp.exe has been seen being distributed by the following 4 URLs.

http://www.sharepresentcentral.com/c?x=wzQxL6Mezh0YgR4OOLlElxhXkU7MYAEbl/BJukGROlk=&c=K3Iccnejb HfvL3/FgoN OkxesiQd7AaNXsHUu9c5CRzrugagDYZiASPXeyxaqDmKwkSu91rUKPDhWPbmiHvixfe5qg/u32STe7lHTKZxmQx3eDPDF3iYPAIXj0lBHNzbHmqnu5JzYwZdSjAZK0BS09jmGOhRjcniyktK82CGy4=&e=0&downloadAs=FVD2015Setup.exe&fallback_url=http://www.finalvideodownloader.com/.../newest.exe

Remove 7e382dec_stp.exe - Powered by Reason Core Security