softonicdownloader_para_itunes.exe

The application softonicdownloader_para_itunes.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from sd-cf.softonic.com.
MD5:
203cba986446537c3ee4657d581f83f9

SHA-1:
e2e32c8a1ff740df45c6c83c6dc654f3d24b5996

SHA-256:
cf3d25a0daf860457387bdba6eb7944461854184913b996858bb5a7f74d8d809

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 6:04:46 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softonic.Bundler (L)
16.8.5.23

File size:
376.4 KB (385,436 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\softonicdownloader_para_itunes.exe

File PE Metadata
Compilation timestamp:
4/23/2014 9:21:29 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:yZ99w9e/wB+TRTsOJbSTBfSD+XreW9ZXeRLIZLpGImcyZItGY0YeYoSZzeK0ZJGL:yZ99wWh1s2WXiWXXfUImcyGm6oSZF82

Entry address:
0x52DD40

Entry point:
38, C1, F8, 05, 8D, 04, 02, 66, 89, 85, B0, 01, 00, 00, 8B, 44, 24, 58, E9, A0, 00, 00, 00, 89, F1, 29, C7, 29, C1, 89, D0, 66, C1, E8, 05, 66, 29, C2, 8B, 44, 24, 38, 81, F9, FF, FF, FF, 00, 66, 89, 90, B0, 01, 00, 00, 77, 16, 3B, 5C, 24, 4C, 0F, 84, A1, 04, 00, 00, 0F, B6, 03, C1, E7, 08, C1, E1, 08, 43, 09, C7, 8B, 74, 24, 38, 89, C8, C1, E8, 0B, 66, 8B, 96, C8, 01, 00, 00, 0F, B7, EA, 0F, AF, C5, 39, C7, 73, 20, 89, C6, B8, 00, 08, 00, 00, 29, E8, 8B, 6C, 24, 38, C1, F8, 05, 8D, 04, 02, 66, 89, 85, C8...
 
[+]

Code size:
336 KB (344,064 bytes)

The file softonicdownloader_para_itunes.exe has been seen being distributed by the following URL.

Remove softonicdownloader_para_itunes.exe - Powered by Reason Core Security