sothink-web-video-downloader_1.2-build-81030_setup.exe

The application sothink-web-video-downloader_1.2-build-81030_setup.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.findmysoft.com.
MD5:
63837efeacd27bdad0be058cceabbe69

SHA-1:
503b20cdcd3da9a81e72a17d5bf44330a787c184

SHA-256:
d1e3da745a15f3bd020624a18b006c1b431b4e84718920d274a29dfd3c31704d

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/17/2024 7:24:11 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Generic
7.1.1

AhnLab V3 Security
PUP/Win32.InstallCore
2014.06.21

Avira AntiVirus
7.11.155.242

AVG
Adware InstallCore.ST
2014.0.3972

Dr.Web
Adware.InstallCore.80
9.0.1.05190

ESET NOD32
Win32/InstallCore.AZ potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.S.gen
4.6.5.141

NANO AntiVirus
Riskware.Win32.InstallCore.czbidv
0.28.0.60253

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14618

VIPRE Antivirus
Threat.4788237
29708

File size:
1.2 MB (1,227,896 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\sothink-web-video-downloader_1.2-build-81030_setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:B/Q7VHxxfBoKVXZ163ynsrq8q6JmsBCCByeb:pQ5HvfmKVXq3ynaqH6Jz5

Entry address:
0xD61D0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 10, 43, 40, 00, E8, 33, E0, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7932

Developed / compiled with:
Microsoft Visual C++

Code size:
866 KB (886,784 bytes)

The file sothink-web-video-downloader_1.2-build-81030_setup.exe has been seen being distributed by the following URL.