softonicdownloader_for_skype.exe

The application softonicdownloader_for_skype.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from skype.ar.softonic.com.
MD5:
34ce6a13938a345aa2a9475951cc5506

SHA-1:
93fdf3f9ca140601d9a938634ae152c92e9bd665

SHA-256:
48ea919bd5a21f537939985f0a767dd771c0be9792a72f2cb6f24eceec2a521f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/17/2024 3:51:30 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softonic.Bundler (L)
16.8.6.19

File size:
357.4 KB (366,024 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\softonicdownloader_for_skype.exe

File PE Metadata
Compilation timestamp:
8/25/2014 4:55:30 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:yn7zi9W6hMux6qLm8+DJBtNQvBpaVmsUKVaQ6RRe/fNOk9HEEVZoStCVBK0ZJGe:y7zio6doAmBDJGppa4KVGRROFbpoStCV

Entry address:
0xF7350

Entry point:
3B, 5C, 24, 4C, 0F, 84, 16, 05, 00, 00, 0F, B6, 03, C1, E7, 08, C1, E6, 08, 43, 09, C7, 8B, 4C, 24, 38, 89, F0, C1, E8, 0B, 66, 8B, 91, B0, 01, 00, 00, 0F, B7, CA, 0F, AF, C1, 39, C7, 73, 23, 89, C6, B8, 00, 08, 00, 00, 29, C8, 8B, 6C, 24, 38, C1, F8, 05, 8D, 04, 02, 66, 89, 85, B0, 01, 00, 00, 8B, 44, 24, 58, E9, A0, 00, 00, 00, 89, F1, 29, C7, 29, C1, 89, D0, 66, C1, E8, 05, 66, 29, C2, 8B, 44, 24, 38, 81, F9, FF, FF, FF, 00, 66, 89, 90, B0, 01, 00, 00, 77, 16, 3B, 5C, 24, 4C, 0F, 84, A1, 04, 00, 00, 0F...
 
[+]

Entropy:
7.9612  (probably packed)

Code size:
316 KB (323,584 bytes)

The file softonicdownloader_for_skype.exe has been seen being distributed by the following URL.

Remove softonicdownloader_for_skype.exe - Powered by Reason Core Security