7e382dec_stp.exe

Final Video Downloader

Bitberry Software

The application 7e382dec_stp.exe, “Final Video Downloader - Fastest YouTube downloader ” by Bitberry Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.presentfilestag.com and multiple other hosts.
Publisher:
Bitberry Software   (signed by Bitberry Software)

Product:
Final Video Downloader

Description:
Final Video Downloader - Fastest YouTube downloader

Version:
2016.15.12.30

MD5:
fc87d6d4362be076fcf0de2d2cd89454

SHA-1:
ad1212e80f2bb174eabe81ddf7b0ada94045a562

SHA-256:
f99b6aef050625e10832f91916b1a115ca7693fd0b025660cd43c59b62a154b7

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/15/2024 11:44:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bitberry.BitberrySoftware.Installer (M)
16.1.13.11

File size:
13.2 MB (13,829,688 bytes)

Product version:
2016

Copyright:
Copyright © 2009-2016 Bitberry Software

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\7e382dec_stp.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/12/2015 6:00:00 PM

Valid to:
3/12/2017 5:59:59 PM

Subject:
CN=Bitberry Software, O=Bitberry Software, L=Holbaek, S=n/a, C=DK

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2B45F5EACFCCD01402902F5B86CE6120

File PE Metadata
Compilation timestamp:
7/9/2014 1:58:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:FU07/8HHd/sYFYSDZpCcbU4/a06vBhaeg0E0zCM0feRWnFTA8pM3d3vuEDGSDe:2tlsOvZpfXYXgKSqKFdMtmEySDe

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9989

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file 7e382dec_stp.exe has been seen being distributed by the following 3 URLs.

Remove 7e382dec_stp.exe - Powered by Reason Core Security