softonicdownloader_para_teamviewer-9.exe

The application softonicdownloader_para_teamviewer-9.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from teamviewer.softonic.com.
MD5:
4f1882e76de55df8af191223158b68bc

SHA-1:
33b11ae2249632fbc386dc5aba28c4288add48c4

SHA-256:
b8780019e5b1bc11cfb1f88b4af78e8aed2c92cd43541c1e66311f6dd4d6860b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/17/2024 7:35:32 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softonic.Bundler.Meta (L)
16.6.17.6

File size:
355.6 KB (364,112 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\softonicdownloader_para_teamviewer-9.exe

File PE Metadata
Compilation timestamp:
7/23/2014 3:01:45 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:eGBj8Xn74X8M0rp/04R7Um6Kc/2dgEIUMkeXammIPkMeoVaoSrI9K0EJGy:1lS8X8hs4Rwo0d1xqDOehoSrntd

Entry address:
0xF7080

Entry point:
03, C1, E7, 08, C1, E6, 08, 43, 09, C7, 8B, 4C, 24, 38, 89, F0, C1, E8, 0B, 66, 8B, 91, B0, 01, 00, 00, 0F, B7, CA, 0F, AF, C1, 39, C7, 73, 23, 89, C6, B8, 00, 08, 00, 00, 29, C8, 8B, 6C, 24, 38, C1, F8, 05, 8D, 04, 02, 66, 89, 85, B0, 01, 00, 00, 8B, 44, 24, 58, E9, A0, 00, 00, 00, 89, F1, 29, C7, 29, C1, 89, D0, 66, C1, E8, 05, 66, 29, C2, 8B, 44, 24, 38, 81, F9, FF, FF, FF, 00, 66, 89, 90, B0, 01, 00, 00, 77, 16, 3B, 5C, 24, 4C, 0F, 84, A1, 04, 00, 00, 0F, B6, 03, C1, E7, 08, C1, E1, 08, 43, 09, C7, 8B...
 
[+]

Code size:
316 KB (323,584 bytes)

The file softonicdownloader_para_teamviewer-9.exe has been seen being distributed by the following URL.

Remove softonicdownloader_para_teamviewer-9.exe - Powered by Reason Core Security