sfhelper-setup.exe

SaveFrom.net helper 0.0

Samokhvalov Mikhail Ivanovich

This is a setup and installation application. The file has been seen being downloaded from sf-helper.net and multiple other hosts.
Publisher:
SaveFrom.net   (signed by Samokhvalov Mikhail Ivanovich)

Product:
SaveFrom.net helper 0.0

Version:
0.0.0.647

MD5:
517b7d555c369f9f69f2d59d101f0e0c

SHA-1:
c592cb9180091035e15ad358b64bb8a4d5922410

SHA-256:
e24a6c5db64b6d34301e3ac0c35d72b2b3487dfc7fb08ceff9ef2742a6701e9a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/30/2024 3:41:27 PM UTC  (today)

File size:
6.1 MB (6,373,328 bytes)

Product version:
0.0.0.647

Copyright:
All Rights reserved © 2013-2016

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\sfhelper-setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/25/2016 11:31:12 PM

Valid to:
4/26/2017 11:31:12 PM

Subject:
CN=Samokhvalov Mikhail Ivanovich, O=Samokhvalov Mikhail Ivanovich, L=Saint Petersburg, S=Saint Petersburg, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216F0FB76EA2C96134616CFB08D0F0266A

File PE Metadata
Compilation timestamp:
4/6/2016 10:39:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:9dLIQcMum1vERVkYmEPobnSur676yEul3WCp+xocWTRIMLtH8chGYmDJRn2:9dsJMl1vER21nSAuzp+xVIIwHlhGntR2

Entry address:
0x117DC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 44, 01, 41, 00, E8, C8, 4D, FF, FF, 33, C0, 55, 68, BE, 1E, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 7A, 1E, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 0E, D5, FF, FF, E8, 5D, D0, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 23, D6, FF, FF, 33, C0, E8, 60, 2E, FF, FF, 8D, 55, EC, 33, C0, E8, A6, A0, FF, FF, 8B, 55, EC, B8, 58, 86...
 
[+]

Entropy:
7.3898

Developed / compiled with:
Microsoft Visual C++

Code size:
65 KB (66,560 bytes)

The file sfhelper-setup.exe has been seen being distributed by the following 50 URLs.

http://sf-helper.net/.../file.php?id=default&f=&country=co&ts=1468353490&s=2c969113ea266534c93585de6523cde3adf98f6b

http://sf-helper.net/.../file.php?id=default&f=&country=mx&ts=1469237035&s=89a1b6a773330d99a62ce15ef6fe1e107215f252

http://sf-helper.net/.../file.php?id=default&f=&country=in&ts=1469191451&s=250dca44ecbbcbe9f2b2bd6040a95060d7352cce

http://sf-helper.net/.../file.php?id=default&f=&country=eg&ts=1468805467&s=0c642413791f21918b7d837a1ffe52ed05c4f70c

http://sf-helper.net/.../file.php?id=default&f=&country=us&ts=1468679604&s=b8c8d5f7efbdffa68d57d7e69e40e0a73bcb3e43

http://sf-helper.net/.../file.php?id=default&f=&country=id&ts=1469259359&s=6ab4c76cd57f89ffe63cf2bf7686564a1c898562

http://sf-helper.net/.../file.php?id=default&f=&country=eg&ts=1469318660&s=4f626ae0487b2fc195d4e5d8d619f6a18d50ec38

http://sf-helper.net/.../file.php?id=default&f=&country=dz&ts=1469120547&s=4a1fd5ff6efa08b043373efde652d826d3facce2

http://sf-helper.net/.../file.php?id=default&f=&country=dz&ts=1468440687&s=027b36c4bc3316ce9665b12e72a9a6e4dc5dd9c4

http://sf-helper.net/.../file.php?id=default&f=&country=sa&ts=1468453628&s=b065ae7d57e35ac37b43762a3d6f0c57ffe1d980

http://sf-helper.net/.../file.php?id=default&f=&country=in&ts=1468837546&s=9b1be2cbae973db61421b670d5828bea7372b201

http://sf-helper.net/.../file.php?id=default&f=&country=dz&ts=1468352750&s=776221b588450ba84629c9d1574aa864c231677d

http://sf-helper.net/.../file.php?id=default&f=&country=af&ts=1469302899&s=a4acdb66a24e2c6929717ca39924290a7056858d

http://sf-helper.net/.../file.php?id=default&f=&country=co&ts=1469402826&s=fb33e40bb8c097200aad645c5615c21433451089

http://sf-helper.net/.../file.php?id=default&f=&country=id&ts=1468669813&s=277534c946bde6c95e726f3cf612acbdbf91bdf2

http://sf-helper.net/.../file.php?id=default&f=&country=us&ts=1469062079&s=ad09da945f5a2119352a18d7b2c054dbf91c6fff

http://sf-helper.net/.../file.php?id=default&f=&country=dz&ts=1468414155&s=c87369101950230001df3ebcd3b7c2b8c6f27ef5

http://sf-helper.net/.../file.php?id=default&f=&country=br&ts=1469549361&s=b9adc226288b9a771589978398da669aaa02e0b1

http://sf-helper.net/.../file.php?id=default&f=&country=bd&ts=1468772054&s=5e41ad338268f499603b095b852f4849aa7b59b2

http://sf-helper.net/.../file.php?id=default&f=&country=mu&ts=1469212886&s=af2fab648573e77ac43f9675e6ba63afdc540adf

http://sf-helper.net/.../file.php?id=default&f=&country=pk&ts=1468679673&s=d2b089aeac384d00d0ef973f2a30e2ee9b5a9698

http://sf-helper.net/.../file.php?id=default&f=&country=br&ts=1468502479&s=cce0ec3d035db0fa1110443e726a4e4197935939

http://sf-helper.net/.../file.php?id=default&f=&country=br&ts=1469447251&s=b3e3b5e2d1187ba080a29bd1d680a7dd77388a9c

http://sf-helper.net/.../file.php?id=default&f=&country=ng&ts=1469497166&s=04ac8beab650eb5834b969b790753ee41fa0bb8e

http://sf-helper.net/.../file.php?id=default&f=&country=id&ts=1468670827&s=adf88415d8d8919662c68421dc6436d00edeb397

http://sf-helper.net/.../file.php?id=default&f=&country=ph&ts=1469077511&s=6a0f53ad244972eb18bef3bd3dd20916f97f3999

http://sf-helper.net/.../file.php?id=default&f=&country=in&ts=1468413055&s=2371fb905c0bdc72851d4cd0fdbcf25dd9c073a4

http://sf-helper.net/.../file.php?id=default&f=&country=in&ts=1469080724&s=7e476ac14ddecfcb4fc4a76e1066ef3edc1969cb

http://sf-helper.net/.../file.php?id=default&f=&country=id&ts=1469001006&s=b6350f9bc10609b95d5c837852a3a49bdf83c788

http://sf-helper.net/.../file.php?id=default&f=&country=dz&ts=1469051161&s=80905950b85c528801d0d3253772ea0a7669d495

Latest 30 of 1,132 download URLs

Scan sfhelper-setup.exe - Powered by Reason Core Security