softwareetrog.exe

SoftwareEtrog

Internet Rimon Israel 2009 LTD

The application softwareetrog.exe, “SoftwareEtrog Setup ” by Internet Rimon Israel 2009 has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from software.neto.net.il.
Publisher:
Internet Rimon Israel 2009 LTD  (signed and verified)

Product:
SoftwareEtrog

Description:
SoftwareEtrog Setup

MD5:
ec3534c3f88ce4996f5a5dc51d79ed7a

SHA-1:
b5ac70f1e31d2f20e3ee5612b7f4ffe1ce9cefc2

SHA-256:
d4a1d601bf84a681d5fd48fb0fd79dfc15cb4a837117ca89df4274e6414cf90b

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
11/6/2024 4:56:11 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.Generickd|2|103!c
2.1.4+

Bkav FE
W32.HfsAdware
1.3.0.8383

Dr.Web
Win32.HLLW.Facebook.2521
9.0.1.0263

ESET NOD32
Win32/NetFilter.A potentially unsafe (variant)
10.14138

Fortinet FortiGate
Riskware/NetFilter
9/19/2016

McAfee
Artemis!EC3534C3F88C
5600.6272

NANO AntiVirus
Trojan.Win32.Facebook.dwwvro
1.0.38.8984

Rising Antivirus
Malware.Heuristic!ET (rdm+)
23.00.65.16917

Sophos
Mal/KoobRK-A
4.98

VIPRE Antivirus
Trojan.Win32.Generic
52384

Zillya! Antivirus
Adware.NetFilterCRTD.Win32.2656
2.0.0.3059

File size:
4.1 MB (4,296,056 bytes)

Product version:
1.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\softwareetrog.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/3/2014 4:06:21 PM

Valid to:
3/3/2017 4:06:21 PM

Subject:
CN=Internet Rimon Israel 2009 LTD, O=Internet Rimon Israel 2009 LTD, L=Givat Shmuel, S=Israel, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E009CE6A8C6688EC6901BAD45E51B46F

File PE Metadata
Compilation timestamp:
7/9/2014 10:58:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:MoUq6AnfOijBEZf7o3xd4jdqzublbDCA+rx:iq6AfOCBmkBIdgcDtUx

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9883

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file softwareetrog.exe has been seen being distributed by the following URL.

http://software.neto.net.il/SoftwareEtrog.exe

Remove softwareetrog.exe - Powered by Reason Core Security