SoFo.exe

Sofo Player

CipSoft GmbH

This is a setup program which is used to install the application. The file has been seen being downloaded from mega.nz and multiple other hosts.
Publisher:
CipSoft GmbH

Product:
Sofo Player

Version:
8.54

MD5:
dee7364824c828aa94fc21c0878fc9c4

SHA-1:
46f2fd318acfab148b8c600800653f63421bba58

SHA-256:
c6320fd0767cbf7eb7c6628ddf4c652689ef793e89a45197c0b578a53f2c2e54

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 7:55:48 AM UTC  (today)

File size:
28.4 MB (29,795,609 bytes)

Product version:
8.54

Copyright:
SoFo

Trademarks:
SoFo.

Original file name:
SoFo.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\sofo.exe

File PE Metadata
Compilation timestamp:
12/8/2009 10:45:51 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:7NXiTifRpBwqUx22DtGtLi4RwRnHRbVInco/3OzO+Yvn/89aagDAyBunSfSYITw5:7V0aRoqf2pnMsHRe38M/ejTnSMzndR2

Entry address:
0x3E3B33

Entry point:
E8, 00, 00, 00, 00, 60, E8, 4F, 00, 00, 00, 7F, F8, 73, 02, 14, 7E, 67, D5, 00, 4D, 7B, 0A, C7, D4, 61, 18, E9, B3, 7D, E8, 5C, 87, DD, F0, D9, 17, 0E, CB, C7, D0, 7F, 8B, 0E, C9, B1, EF, B3, 74, 57, 82, C2, F6, F9, 69, BE, D6, 13, 9A, 4A, F4, 9D, 80, A1, EA, CD, C2, 4A, F4, 9D, 80, A1, EA, CD, C2, E9, 1A, 6D, 00, 00, E9, 2E, 6D, 00, 00, E9, 29, 6D, 00, 00, E8, 6E, FB, FF, FF, 6E, 04, 01, 00, 82, 99, 00, 00, 63, 5B, 2C, 14, A9, B6, D1, 46, 2C, 20, 74, 06, B2, 24, 91, 3F, 42, FE, D0, 4D, 77, 1A, 69, 55, A5...
 
[+]

Packer / compiler:
MoleBox v2.0

The file SoFo.exe has been seen being distributed by the following 2 URLs.

https://mega.nz/temporary/.../iQs13ZIS

Scan SoFo.exe - Powered by Reason Core Security