ultrazipsetup_s.exe

UltraZip

Softmaking srl

The application ultrazipsetup_s.exe by Softmaking srl has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.softonic.it and multiple other hosts.
Publisher:
Softmaking  (signed by Softmaking srl)

Product:
UltraZip

Version:
2.0.0.0

MD5:
947d0b26a77c7e4a4a515212c57150fb

SHA-1:
3d416c0c9f38f05b96c47b9579e64c61c2576746

SHA-256:
78af572d19e8880d0b2cace63a3009960d12ddfb932b826a4d5b8b4dc7cff5a6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 11:15:18 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softmakingsrl.Installer (M)
15.12.9.22

File size:
3.4 MB (3,576,976 bytes)

Product version:
2.0.0.0

Copyright:
© UltraZip 2015

Original file name:
UltraZipSetup.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States d'America)

Common path:
C:\users\{user}\downloads\ultrazipsetup_s.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/7/2015 2:00:00 AM

Valid to:
11/27/2016 12:59:59 AM

Subject:
CN=Softmaking srl, O=Softmaking srl, L=Roma, S=Italia, C=IT

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
32D48A01B0F42131BAB98E502CE0393D

File PE Metadata
Compilation timestamp:
10/7/2014 6:40:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:5H46WovM0K4HTjQjckwQH6F2xzZf4/V4/F:5Y1ovXKaTjQjckw862f+c

Entry address:
0x3217

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, B8, 37, 42, 00, E8, C0, 2D, 00, 00, A3, 04, 37, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, B8, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, 00, 2F, 42, 00, E8, 6A, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 58, 2A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file ultrazipsetup_s.exe has been seen being distributed by the following 23 URLs.

http://www.softonic.it/sads/tracker.php?ev=c&co=GB&sid=d252227a5e010c36eaf388d2095986f8&upv=2d3b81f83b8768baec93b6b6dbc85954&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA98910B6DFA619EEF67E9A0968BAE6328519C275E9F0B9148DBFDC68F0F86CB743ED4948A4B1E78136A829060E3E70689E7593727B668750516CD4DB26A03847FE5FFA4DBC67A895B6094DF2BCB087E9A8BCD3FA125A6C7C56E8EC8CD97A47FC88C89655B87FC1DE66EBCB2BA6175311EDE1C7BD22CFB12374A708964671AC85C8375CC71095DDBC8587843157AB5511B2F9C6BF69D6B4035C53557FA327E059C&h=CD1D5D33FD1D66791F4C4962A9149A8D2A47AB520092D8EEBD4195D95F33E8ED&directdownload=1&f=69703343&d=http://www.ultrazip.com/.../UltraZipSetup_s.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=92b6bcb3b746a215347e8421dfa84e94&upv=541370169f90cf567f7009f870dcccc7&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA98910B6DFA619EEF67E9A0968BAE632821063482143B08BA5470A202980AC3350A2DB4D61E142897F241D4BBA73FC0A91BF1166B64B9802437694902208C7D41819436CEA0B99CF582FAD457896892624CC24EBD765A9D67EBDECF045C16DF41BC2763B73F229155AC2567D7B2C5BD842EB4968860B2F94BC002FEB726A768CA241F58A44F4F202FA66C246DBA8BDFA21840463B10B10D9E1425E4829985B1F0&h=EF88A7A7F3C1BA05BF1B1E5D27DC09D9CE8DDDB7359579FDDECEF604BFCA15C8&directdownload=1&f=69703343&d=http://www.ultrazip.com/.../UltraZipSetup_s.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=510536a816b7a2c45f0b546cf2dacfb9&upv=f67bdb4d4f7aa9313bcb24b44a0a020e&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA98910B6DFA619EEF67E9A0968BAE63281C5451185C85D0F001FAFC3B866890B682093AF2466F19654999182759EBDE2AA6423BC170E5FA3A00890A4FF05AF298344E0DB783F7693597DE97132676B7AE39C3B06B60AE04B91A8D25C657DFA2ED5B0E9217189FCD4AA76F410FF310302064B158DAEB5DEBC4BB587975D3E70D24635F41F1298E02486352095F55A471090D728E7E19F482600F98B1E3B5233398&h=28DA83BFF055E1114ECB5776878D811599A2324B1E089443C506236585426367&directdownload=1&f=69703343&d=http://www.ultrazip.com/.../UltraZipSetup_s.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=334e9ca3424f23fb05a4ec72612c64ae&upv=e061a9323e1a11d05cbdd92a008509d7&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA98910B6DFA619EEF67E9A0968BAE632879B3B1AB69BDF34FCDF4E1803882DC4E968BD0F4754BC8617AC21D7E680D165359547E68AA93EEC555BBBA43BFB78A5C0713A4F3C02B3FD8F97F56F4DB07B2549CF6555E699202B028388C7FD12F65F7682EAE6CE59992F69757BFFC19A450E24B5D91B7FEA70C22FEC0D1E603A7D13E2D700D095C0AF67B71D1326614DFAF04749F55D12F71EE4E87A48EAE080B5DD7&h=7446A16E3F52C142671FB5A8BB930BBA3701219F4D62FD7DF1AF33706C1C92A8&directdownload=1&f=69703343&d=http://www.ultrazip.com/.../UltraZipSetup_s.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=53b6152da94a669ba6404a223572a5ac&upv=1af05f472f2295bc35c87aa65f21a48a&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA98910B6DFA619EEF67E9A0968BAE63287E076F3CD7328DA5D4FD799FD6E6AFBD8E014F4BB0BD662638BAFF023C1C0F244E5B23F835D04114A8384C84F09A99DBA33393AB6383F2614490F82C2A9EF39B4CF339B2571080EEFF04F2C9BCBB5840EED87F1E63A0E4346F626B33F15FD727CA2C275F420810469DA731CFC2AD1D6882B3776E0FCF1919A0C1E3659A7822ABCE505D461A2604DD00804C2F4F947071&h=04168B7552921E8DECBD46F64C2E4F931238E91C83CD7097AE98574B9075DD24&directdownload=1&f=69703343&d=http://www.ultrazip.com/.../UltraZipSetup_s.exe

Remove ultrazipsetup_s.exe - Powered by Reason Core Security