softonicdownloader_para_gta-san-andreas-homeboys.exe

Application Installer

The application softonicdownloader_para_gta-san-andreas-homeboys.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from gta-san-andreas-homeboys.softonic.com.
Product:
Application Installer

Version:
1.41.8.2

MD5:
be967c1eaaeccffe2c6ec0e8461b1c33

SHA-1:
885a3fdee4b76d81e0102029a6ba974f380f222b

SHA-256:
088bf185a94d49f80309ae7a17eb60c9b477c473b9e523553ba3951093ae9fcc

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
2/26/2025 4:30:28 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softonic.Bundler.Installer.Meta (L)
16.4.23.20

File size:
435.4 KB (445,816 bytes)

Product version:
1.41.8.2

Copyright:
Copyright (C) 2014

File type:
Executable application (Win32 EXE)

Language:
Spanish

Common path:
C:\users\{user}\downloads\softonicdownloader_para_gta-san-andreas-homeboys.exe

File PE Metadata
Compilation timestamp:
11/5/2014 12:01:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:ISXd1O2A49M3bBKncHcFhE+a8AdL3U3oSscCA48L:fXaUu3Qc807DdrzQ40

Entry address:
0xFA090

Entry point:
0F, B7, C2, FF, CB, 41, 02, E6, 8D, 1D, 0B, 5C, A4, DC, 81, E8, 88, C7, 85, 0F, 4A, 84, C7, 22, F8, C7, C6, 87, EB, 73, A1, 8D, 15, 85, 3C, 90, C4, E8, 18, 00, 00, 00, 69, F2, 17, 71, C2, 33, F2, 85, F3, C7, C1, EE, 64, A2, DD, 72, 05, 14, D9, F6, C0, 23, 3B, DE, 03, EB, 80, D8, 1D, 89, DF, B8, 24, EA, E2, A2, 29, E9, 0F, AF, C3, 87, F1, 1D, 69, F7, 1B, D2, 8B, DE, 02, C6, B8, 45, 1C, D7, 9E, 69, FA, EE, BC, 61, A1, 01, FD, 39, CE, 33, D3, B1, 0E, 15, 1F, 06, 83, 18, 80, E5, 86, 5D, 88, E5, 81, F3, C0, A9...
 
[+]

Code size:
320 KB (327,680 bytes)

The file softonicdownloader_para_gta-san-andreas-homeboys.exe has been seen being distributed by the following URL.