softonicdownloader_para_firefox.exe

The application softonicdownloader_para_firefox.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Softonic Downloader installer, however the file is not signed with an authenticode signature from a trusted source. With this installer, users are expecting to download the free Mozilla Firefox web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
MD5:
4b8be2403cbbd07cfe09219a0949930e

SHA-1:
50ed1c771082594ca943162a83f25ba4444d45cb

SHA-256:
7313290573976a09a8b0992d965468b8b4788ff5159850b91cfa38f77a828d6e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 8:35:03 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softonic.Bundler.Meta (L)
16.6.2.3

File size:
358.3 KB (366,944 bytes)

File type:
Executable application (Win16 EXE)

Bundler/Installer:
Softonic Downloader

Common path:
C:\users\{user}\downloads\softonicdownloader_para_firefox.exe

File PE Metadata
Compilation timestamp:
7/23/2014 10:18:12 AM

OS version:
5.1

OS bitness:
Win16

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:2w9GgFlEOUStVJh8+TF+qpQ4cCsw5LfYSj/jBLvMbJ1oSWIIK0ZJGg:/IaVJ+onWXKASjjBLKoSW+85

Entry address:
0xF7090

Entry point:
60, BE, 00, 90, 4A, 00, 8D, BE, 00, 80, F5, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 08, 59, 0F, 00, 57, 83, C3, 04, 53, 68, 87, E0, 04, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
316 KB (323,584 bytes)

The file softonicdownloader_para_firefox.exe has been seen being distributed by the following URL.

Remove softonicdownloader_para_firefox.exe - Powered by Reason Core Security