alsong.exe

ESTsoft Corp.

This is a setup and installation application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
ESTsoft Corp.   (signed by ESTsoft Corp.)

Description:
ALSong Setup

Version:
9.3.6.01

MD5:
7d822378d3f8cba2f0deaba60675b9eb

SHA-1:
0e1467cedf413e6c0bb3b40058e714beb73003d9

SHA-256:
2a926e3ab5c3fb526cd4a061f98f3f589e52507d1e5ea47478a08131d33b679b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:30:39 AM UTC  (today)

File size:
10.1 MB (10,629,416 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\alsong.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/19/2008 1:00:00 AM

Valid to:
11/20/2009 12:59:59 AM

Subject:
CN=ESTsoft Corp., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ESTsoft Corp., L=Gwanak-gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0C0BA5C20E64CCAA47E70BAE991D33FD

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:K07Race/K416jlENQWpuvenloW0efcRiXv/fyI7Gh4ohV5RleSG0:Abs2vzlHHih4o75RleS/

Entry address:
0x41514

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, D4, 89, 45, A8, 89, 45, A4, 89, 45, D8, 89, 45, DC, 89, 45, E0, 89, 45, E4, 89, 45, F0, B8, 7C, 13, 44, 00, E8, DF, 49, FC, FF, BE, B0, 41, 44, 00, 33, C0, 55, 68, 2A, 1C, 44, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, AC, 1B, 44, 00, 64, FF, 32, 64, 89, 22, 33, C0, 55, 68, 84, 15, 44, 00, 64, FF, 30, 64, 89, 20, A1, D4, 34, 44, 00, E8, 02, FD, FF, FF, 33, C0, 5A, 59, 59, 64, 89, 10, EB, 2F, E9, 6B, 1B, FC, FF, 6A, 10, 68, 3C, 1C, 44, 00, 68, 50, 1C, 44...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
259.5 KB (265,728 bytes)

The file alsong.exe has been seen being distributed by the following 23 URLs.

http://gsf-cf.softonic.com/0e1/467/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55163&instance=softonic_en&type=PROGRAM&Expires=1477549540&Signature=YjCdu637jLJWqmg9QB8ZWQh5FY941aFDFpIKUvrCBH8RZL-QKSN9ecuabP9VNQ-byEG08z7qHDDoQgebxcGitWDAdRXk71BeI8Ru9bs~tyU3r2lcMNuw~8FeVx8rE1JPEA-Ce~I8jJqvqLVG1tHN4uMcss~D2pGFVaJJrEMa8XI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ALSong.exe

http://www.techtudo.com.br/_/software/.../download

http://s6089.chomikuj.pl/File.aspx?e=FY44UlO7ZWD_Nt6zMxQgqKK8CpwgVD5LYCXvOlXybVGzDWvpYzgF-zGio50lFpgc59B9YLPUabPHFT2ssaLISPEJLdVrWkhBDSmVRpzD1BzGrxVUZsocp3k0GlBnwV5Z_lNF8dntbtWMyyrEo24iaQ&pv=2

http://gsf-cf.softonic.com/0e1/467/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55163&instance=softonic_en&type=PROGRAM&Expires=1479242089&Signature=Vv~1Ap5KwIssUGDy66XVt~DCrZ4XXXt-RDYJ0LTGlhFseZ4y1gmKtVS8ZqdOpjaq-70G2CyiIUAk6Uwz8gFhd81nHan0onEUjVITeIbtu9bjbP4zUjOo6JADnOP6SHt0suyESAAuGCQXeOw~JegBKbYA9tT-NFd33pI9bgkyrT8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ALSong.exe

http://alsong.de.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAO7ssCxytyg/p9s9GgRkrvmYeiuzKaGgnXa6zKKKPyliasmEySVPYl8EwHaqo3X/hAW32uuM1szvGsnoO61v80A2FWDrV/mF4wUxLs/.../3k=

http://gsf-cf.softonic.com/0e1/467/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55163&instance=softonic_en&type=PROGRAM&Expires=1460931496&Signature=Dj3u4zctXL2V1Fblc8QvN3Grs2UeFNdgXovmQGQfSaJOieRDnGqAsKer9YNIIzsa0MzsxsqfS4h0xroQDSxoDlTGHNlyWYSPmzNWysi1GoNzbWJshFlIzMH-ts--vluOQ4Vumqf0ZebYLVqD8u4BM9b8u-adbOK8SEkztu~2918_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ALSong.exe

http://gsf-cf.softonic.com/0e1/467/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55163&instance=softonic_es&type=PROGRAM&Expires=1479813055&Signature=VD06wOK0E6YcK5I5gSxHpaVXQOyiNqdDPGuh8AW5oAI7tIXl-jA2Me4q-O75qv5ZYRkBOSNmfaBQHbq8syY3GtMn7bUcucEoJWKgvDV0HYw8GBIGuWS6toaXktjOJ2-zsPsA8vzUTNwZWIJRwusTuO5gSTe~Z4ycLjs6REMxBII_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ALSong.exe

http://gsf-cf.softonic.com/0e1/467/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55163&instance=softonic_es&type=PROGRAM&Expires=1478146788&Signature=bpob7R1Gp1qvyY3MtsrP5ipE9xCBy2wjmhRFwBDrYBTia9e1QgYXIUg15Q9jGVWM2qLhMJVgzzvSWtKPESM35uXajoFBWWWJKn4lG501mn70kvdVjYKI9L28084uN-qUb7et8nX6lLNHulJAlwDbO4UWkuwrXsIrddHKTd4gnbg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ALSong.exe

http://gsf-cf.softonic.com/0e1/467/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55163&instance=softonic_es&type=PROGRAM&Expires=1435270908&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=byCmQrJmcNJGH92NvObF58lpA2tkUxBo0-L5Me~qnV-ar6jd1JfVeDBrqgzQErMcyJ-wbd23xcilL8HRGugOl6R9JU~CYtQVa1ZM3HWSzlnKC-ovh3IOTbzZI0U-d6Zytuc-uJRRytmB23hiVOixE~s2CxzAhzEW8lbyZUQA0ww_&filename=ALSong.exe

http://gsf-cf.softonic.com/0e1/467/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55163&instance=softonic_br&type=PROGRAM&Expires=1478130908&Signature=MouzP-ws1hHgqt1j8oNjLtcysfCquau5lBQ7yARX-CbfyXwYx1BzU84QMPm6BVjlzDpZKxyjDcjg89V2aOn42fp5~Zue1ujZyN6WTZ-~YsO~jL~9nULAf7-exBhs9PlPrwafmEfx~vmXyWKWKdlGEnpIseBLSxkdB7H3hOj1-AA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ALSong.exe

https://alsong.en.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAO7ssCxytyg/p9s9GgRkrvmYeiuzKaGgnXa6zKKKPyliasmEySVPYl8EwHaqo3X/hAW32uuM1szvGsnoO61v80A2FWDrV/mF4wUxLs/.../3k=

http://gsf-cf.softonic.com/0e1/467/.../file?SD_used=0&channel=WEB&fdh=no&id_file=55163&instance=softonic_en&type=PROGRAM&Expires=1469215132&Signature=HWFZWDPpqdOdOPllvuB38cK1ysUFKtbjpjQvQBwGmDeNChZ8Cngk7W~cun3LSVfAk1Sj5iIY9BY3oXO0t9M802bIpYYtVuXxlNr-z~IVAMz8BPhDPc1H-V-gSqOcze8usJgLugt7BcSCCgKj1fDxzACRfKdgtOLD5hBXKe4v4Cg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ALSong.exe

Scan alsong.exe - Powered by Reason Core Security