8514567_stp.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
MD5:
28319a3f24b1f944223fbd9aaef6f52e

SHA-1:
6b75d8b8b24e3071b07812860239369fca53dd99

SHA-256:
a8bb0c15e37b63bdb30fd66e80b1ed01f73bacc5e9133d94c7ea59bb31b271da

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/2/2024 3:31:14 PM UTC  (today)

File size:
1.3 MB (1,369,131 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\8514567_stp.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
24576:vLhJIFfBg4b97i1vsLJKHNX13vW56ZbX+4qM44XLec99pREgQ8Y7jyS:vLhJCfBgo97i1se13S6R+yjXLhbREgEH

Entry point:
4D, 5A, F5, 01, 1E, 00, 01, 00, 06, 00, 89, 0C, FF, FF, 00, 00, B0, 5F, 00, 00, 00, 01, F0, FF, 52, 00, 00, 00, 14, 11, 50, 4B, 4C, 49, 54, 45, 20, 43, 6F, 70, 72, 2E, 20, 31, 39, 39, 30, 2D, 39, 32, 20, 50, 4B, 57, 41, 52, 45, 20, 49, 6E, 63, 2E, 20, 41, 6C, 6C, 20, 52, 69, 67, 68, 74, 73, 20, 52, 65, 73, 65, 72, 76, 65, 64, 07, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B8, 32, 10, BA, F6, 3B, 05, 00, 00, 3B, 06, 02, 00, 72, 1B, B4, 09, BA, 18, 01, CD, 21, CD, 20, 4E, 6F, 74, 20, 65, 6E, 6F, 75...
 
[+]

The file 8514567_stp.exe has been seen being distributed by the following 13 URLs.

http://gsf-cf.softonic.com/6b7/5d8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=13607&instance=softonic_en&type=PROGRAM&Expires=1481718241&Signature=QxgXxiKQRdVTilLry5ST-U2p2uR7JjzXMzo0PpwDZ0ucSlKD5YpV3R3Uu9tzVImWlK8q70n5aphp0EA3fLZvFL~IIdVQZTc6-4OIU9hs3CscKtW73AJ6-QRt~xBv373Nd6f9ZZNW74mh9-X4jsOQvaxNsr2iA2yw-xAwwyl8aMA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=johncast.exe

http://gsf-cf.softonic.com/6b7/5d8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=13607&instance=softonic_en&type=PROGRAM&Expires=1485766247&Signature=LoYAD~BDMOsWu7OdWbdmGV2NQPQ4aobHsUSYmWuqeejeN-4bYRxTduCHyTH1LlfzmSHhH~232ZeQeBwxE41e224SJNKlpJ6ZC9CHZtMtvELe2ASVr~mdafQ0DRs0rBaV2iSq9x3z1RkZROCPE8KZp8tjSvAUjfZF95GDhcBHIxo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=johncast.exe

http://gsf-cf.softonic.com/6b7/5d8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=13607&instance=softonic_en&type=PROGRAM&Expires=1483488139&Signature=T7nmDvYP~3B0DFjm0O01RcXrWDVDtUeqACF8EZ8QQtfw5g08RpLn5CT8v2d~cOOsB5otaKM1dw7zAynhOiSWkY7fueqKPqNc44MzjA5oA-~8W2F2lwCG9Qaej~bHz9URmXxaf9WBmYYLjm1sskGluX~CeYPVNTXv1blSLk4bxaE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=johncast.exe

http://gsf-cf.softonic.com/6b7/5d8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=13607&instance=softonic_en&type=PROGRAM&Expires=1481536485&Signature=VJYEPH0z1niXbe3FMVwZHLdSQll4S6nurW5x8kVadgh~sa0VXjJ5caTOCEIRXOn~msj8vEOQ2Z826wF~BIOymAsVCcWG1EQylTQrkLDWLo3hQJjxJQBz91aFDS8yVQh8b4K6zWB8okGPQuaNzfiMdMyAbNmrFeSbba0tyWHVB~Q_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=johncast.exe

http://gsf-cf.softonic.com/6b7/5d8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=13607&instance=softonic_es&type=PROGRAM&Expires=1467311156&Signature=WmwjARkOYWAao95Z5n0ThTsd3NC1yImQ9jq576H7o8telitkCGcr8ku0NNRw96mkxwOaS1C9YlRwgbq1K5aO-TTJ6z5qICCkXekxdFmtsUnT9S2vlf~Skk~oZrnu~Qtn40~y2XE2mFTdnWiXOeGF-zCrY-d~1i9GwYiDSFc~0cs_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=johncast.exe

Scan 8514567_stp.exe - Powered by Reason Core Security