ultrazipsetup_s.exe

Softmaking srl

The application ultrazipsetup_s.exe, “UltraZip Setup ” by Softmaking srl has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.softonic.it and multiple other hosts.
Publisher:
UltraZip   (signed by Softmaking srl)

Product:
UltraZip

Description:
UltraZip Setup

MD5:
bbc50c6f350fa714ff34da8afa746d75

SHA-1:
91c70374ce91a35b8eef8c8abe5a19837b7f588b

SHA-256:
11bf3e8426af8fee5abcf5c1df1ef21a9cd232d5f47fce67f738b4a6cda92a81

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 5:07:19 PM UTC  (today)

Scan engine
Detection
Engine version

Malwarebytes
PUP.Optional.Bundle
v2015.10.23.01

Reason Heuristics
PUP.Softmakingsrl.Installer (M)
15.10.23.13

File size:
5.4 MB (5,708,608 bytes)

Product version:
2.0.0.9

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ultrazipsetup_s.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/7/2015 1:00:00 AM

Valid to:
11/26/2016 11:59:59 PM

Subject:
CN=Softmaking srl, O=Softmaking srl, L=Roma, S=Italia, C=IT

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
32D48A01B0F42131BAB98E502CE0393D

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:ArP+B9yjvK2RttBKmDA2Ldc3GzfeGQRJlFyiI+pPcW4GtMKrtAUi+iQcT+A:GuyTdDA2Jc2zfeGQRX1PltMKxeQcT5

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9991

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file ultrazipsetup_s.exe has been seen being distributed by the following 17 URLs.

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=67ad00870181025f4baa98b3d8946210&upv=a734f87766bc29dc540ef611baeb321f&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA98910B6DFA619EEF67E9A0968BAE6328519C275E9F0B9148DBFDC68F0F86CB744560F9768A17ABC33DF21A9668CF4F04BD1B032EE30D235F48D94FE4CB1304F3B4CA82E92D9FC09B87B250AB54B237774FAD9CE691D7EFF29CB86A6ED9C5F0A6A13584D79E4E20DD320BF3E8C07D3B9F704CC04BEF49D5A2D42DCC877A6BC43F46C521E6AF88C0F6370CE47C7DCC224453E01705344805ED23C3667847564FCC&h=9593560A4C3B788F8E2A0282C732A7E065BFD7312A98270CEDCF4B63B5969659&directdownload=1&f=69703343&d=http://www.ultrazip.com/.../UltraZipSetup_s.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=3d0a5cfae59cc522dad550681426962b&upv=71cf975f0972164da892e4531fafe9b7&z=results&sk=0&abp=1&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA98910B6DFA619EEF67E9A0968BAE632845FB254314823EE67ACA1DE3E27EA2B95AB1D271886245E73BF363318369BE1AECA9AE75EEADF5E5299A9DFE3995D68C5422DFE9939807433E70DA1D75592D57070B037229CBEA0EBBE145A222D822A79708A4AF65917E3A7D40E342831018FA69467298D19BBDA27A5CD63E3DDDDE471100D0F5845D7ED7993F15D39853C217A4072842A34708B92E52971FEB74835B&h=7FBC21E8B1FA92266EA779920182C89EFCEC5C3F5E18A33B9C6815CEB6DAA855&directdownload=1&f=69703343&d=http://www.ultrazip.com/.../UltraZipSetup_s.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=AT&sid=fbffb4f3c6432381d8e3675a31f03bd6&upv=88959cb28373e2538ffa738124f77824&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA98910B6DFA619EEF67E9A0968BAE63287E076F3CD7328DA5D4FD799FD6E6AFBD3BDD628AACCA3F27927199A575B1AE26517A53CFD324A27EFF188220BA838564B06577845E26169509CAB70A2DC5817349AA74EA77835883EC51B73BC3C8ED3000FA1D3E9B852E752DF8A956E69EB0F2A5A3E891C7037F35971115E8F36BF8BD57D59210D0448AB00252A936E2BEDA93439395E1F0E9C62B992AF1BFF848D352&h=08F1F57891FBBA6FCE505059E7784E4DEF7729E80ACB838188D2D2B0926136A9&directdownload=1&f=69703343&d=http://www.ultrazip.com/.../UltraZipSetup_s.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=d88f91908fed8bf48e430e56a60b4dd6&upv=565fd966b1793345b3db0c75aba60267&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA98910B6DFA619EEF67E9A0968BAE632845FB254314823EE67ACA1DE3E27EA2B954F3F2857EA318FF09A54DF71A77BA81DA3EC6D7FE715F503992DD5666A669FD5699E3E00469DBBF99BBDD5E55B88AAF3AB2F7CE2AD21404AA82D389F662466BEFAE0EBEB6E0D72FEDA9A957B4CC1D6F087C7660FC801711DCD302B950E6EF0F9F830C32F7CE556718367B204503B97EBEBA51AA94078BD0DF82BFE5BFDDC752&h=3998217035A0D65FC97A45974B8813F41CB63F5D439788B24247B90D8723149D&directdownload=1&f=69703343&d=http://www.ultrazip.com/.../UltraZipSetup_s.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=0109856f12e01a7e154c057f25b6705a&upv=f65469bdfadadcb92962d999a40e6b71&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA98910B6DFA619EEF67E9A0968BAE632845FB254314823EE67ACA1DE3E27EA2B99A31C94A6C3FAC712F936A827507E6B289B404BCBA341541842F54F81FD1FD3EED0055BA289AAACBCC9B643E38D75369F1CAED52C23E1C3A4C21CE00E614B71682863307D6D4680E61781BF0A16FD38B5A9ACFFFC2A54805425187BC5D8C7B11795BAC7D289D938D6BAAE8718D78C2C885E703BE306D9E912FA71A0CE7CF932D&h=2F93139D4374C7C9F65BAFB07F8465DD9F8F0DFA907FE1774946DAEF92F3A596&directdownload=1&f=69703343&d=http://www.ultrazip.com/.../UltraZipSetup_s.exe

http://gsf-cf.softonic.com/91c/703/.../UltraZipSetup_s.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=7edde1303979a39822567fb0eeb5cd58&upv=b582d92f73818c9ac9d5fe09c279574f&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA98910B6DFA619EEF67E9A0968BAE6328963FD78BBDF5997409687C6D377559DB7F1010BEF1724766BB30D2170B7410D4DAC9A5A6A1775C6C4CED2E2E10CD992C4DA92E51B2A639462DF1393329F64E75C7FD44B25135FAF0F864213EF3834AD9FC59616EC915DD67B5983D6F9A0A989FE1275A01B29F12810CF87EAD89F10832AF87B19BA51B21CB3B4BE21D46FBECCD9ED5D68E49ECDAA786FA8226ED15B5E1&h=7CB5041A8E9F3D653F37C9051656697884AFB5E78342ECF6EB3660C9E47803AF&directdownload=1&f=69703343&d=http://www.ultrazip.com/.../UltraZipSetup_s.exe

Remove ultrazipsetup_s.exe - Powered by Reason Core Security