tagmachine.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
MD5:
0b02333860a918cdaa60be94cc683c7a

SHA-1:
e8296496021963e4115ef0c3b7ad3121d4ec2a33

SHA-256:
5c449c629ab6adadb46951bada52aa83f16134ccafdd1e8bf71ac7b7f54623b1

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
2/24/2025 8:19:37 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsOval
1.3.0.4924

File size:
593.2 KB (607,444 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
10/27/2004 7:34:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
12288:V3PSp80VCBk+SVMg+rRGJye2DdKrcqj/FbAO0LU7pC1DFUlU:VPSp80Vuk+SGrRXpKx/Z/0LAk1DFV

Entry address:
0x1000

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, 4C, B1, 40, 00, A1, 3F, B1, 40, 00, C1, E0, 02, A3, 43, B1, 40, 00, 52, 6A, 00, E8, 41, 92, 00, 00, 8B, D0, E8, 4E, 17, 00, 00, 5A, E8, 50, 0A, 00, 00, E8, 47, 17, 00, 00, 6A, 00, E8, EC, 23, 00, 00, 59, 68, E8, B0, 40, 00, 6A, 00, E8, 1B, 92, 00, 00, A3, 47, B1, 40, 00, 6A, 00, E9, C7, 70, 00, 00, E9, 1A, 24, 00, 00, 33, C0, A0, 31, B1, 40, 00, C3, A1, 47, B1, 40, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, A4, 00, 00, 00, 0B, C9...
 
[+]

Code size:
40 KB (40,960 bytes)

The file tagmachine.exe has been seen being distributed by the following 2 URLs.

http://gsf-cf.softonic.com/e82/964/.../file?SD_used=0&channel=WEB&fdh=no&id_file=35911&instance=softonic_pl&type=PROGRAM&Expires=1448600352&Signature=W2VP1TdofEr7kxVMD3d7ErdBB9YtKcknJPRDThicwA9L~T2lf1ZM6FCmlpNFg-JP7kyt2NwmtjoPOxECYkqtNyZdzuLQTW0plvCbNA6NwTjExSwsuuZ9ORiO7YABKYvechQ-jLfU4xxdyF1erNYv~qN9gEdAib2EzVI9d8tPxo4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=tagmachine.exe

Scan tagmachine.exe - Powered by Reason Core Security