savefromnethelper-web-760f80dab6-.exe

Magicbit, Inc

The application savefromnethelper-web-760f80dab6-.exe by Magicbit, Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from sf-addon.com and multiple other hosts.
Publisher:
Magicbit, Inc  (signed and verified)

Version:
1.0.0.0

MD5:
d8781a49436908b93f31469dfa2f9058

SHA-1:
c365ac409c0d6a36bf612ba7f07d440cad067cca

SHA-256:
b94fd0fa37bf83901030ae26af212aa92cc0846c646c31d3c745342edff2e7aa

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/30/2024 11:42:32 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Magicbit.Savefrom.Meta (M)
16.3.2.21

File size:
2.8 MB (2,920,832 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\savefromnethelper-web-760f80dab6-.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/20/2014 5:00:00 PM

Valid to:
4/20/2017 4:59:59 PM

Subject:
CN="Magicbit, Inc", O="Magicbit, Inc", STREET="901 N. Pitt Street, Suite 325", L=Alexandria, S=VA, PostalCode=22314, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B5B2652535A2ACE1ACBFF9D5D7816AD4

File PE Metadata
Compilation timestamp:
11/26/2015 10:13:35 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:bHu1sFHX1bjk52SG6rOD5t03yP54J/9k:bHSsFHsra03yP5gy

Entry address:
0x275E00

Entry point:
55, 8B, EC, 83, C4, F0, B8, 70, B8, 66, 00, E8, 30, 84, D9, FF, A1, B4, B4, 67, 00, 8B, 00, E8, 30, BE, F5, FF, A1, B4, B4, 67, 00, 8B, 00, B2, 01, E8, 42, DB, F5, FF, 8B, 0D, 74, B2, 67, 00, A1, B4, B4, 67, 00, 8B, 00, 8B, 15, 98, 91, 66, 00, E8, 22, BE, F5, FF, A1, B4, B4, 67, 00, 8B, 00, E8, 72, BF, F5, FF, E8, D9, 31, D9, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6032

Developed / compiled with:
Microsoft Visual C++

Code size:
2.5 MB (2,573,312 bytes)

The file savefromnethelper-web-760f80dab6-.exe has been seen being distributed by the following 50 URLs.

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-263662286e.exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-6656586970.exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-ce054bde39.exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-3cb4b0e690-[360].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-ef0ca61382.exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-1b57c179cb-[360].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-9da35bf657-[360].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-91a332cd58-[350].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-9122a2926e.exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-07c20e5c9d-[308].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-467c7172af.exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-78139191ed-[360].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-6405dcc216.exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-89b90a9546.exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-934d151bc1-[312].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-e5ddf58fe4.exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-2f74b5b1a4-[308].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-2665e86de1-[308].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-f382170339-[308].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-c3141cfaca-[308].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-40053be738-[360].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-b89f28789f-[308].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-dd9acbc1e2-[308].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-0d02e31cfd-[360].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-8cef6db593.exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-a9020d24d6-[360].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-222d5bfc37-[308].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-879b10ac07-[308].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-82fceac0c5-[308].exe

http://sf-addon.com/helper/.../SaveFromNetHelper-Web-466efceaa4.exe

Latest 30 of 2,781 download URLs

Remove savefromnethelper-web-760f80dab6-.exe - Powered by Reason Core Security