anytogif_setup_ad.exe

Any To GIF

Ye Yizhou

The application anytogif_setup_ad.exe, “Any To GIF Setup ” by Ye Yizhou has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from www.softonic.com and multiple other hosts.
Publisher:
zxt2007.com   (signed by Ye Yizhou)

Product:
Any To GIF

Description:
Any To GIF Setup

Version:
1.0.4.0

MD5:
a04ba29bf308193ec918f32f2794a677

SHA-1:
e4442366bdb4cab879e44686e57eb38d079531a9

SHA-256:
9a7a610626ad2ea180e65dac3b59aedc29da4eb3942275383d77116433745183

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 7:37:56 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Bundler.YeYizhou.Installer.Meta (M)
16.7.8.10

File size:
1.5 MB (1,580,312 bytes)

Product version:
1.0.4.0

Copyright:
Copyright 2013-2015 ZXT2007.com.

File type:
Executable application (Win32 EXE)

Language:
Swedish (Sweden)

Common path:
C:\users\{user}\downloads\anytogif_setup_ad.exe

Digital Signature
Signed by:

Authority:
WoSign CA Limited

Valid from:
9/7/2015 5:00:33 AM

Valid to:
9/7/2016 5:00:33 AM

Subject:
CN=Ye Yizhou, L=Longyou, S=Zhejiang, C=CN

Issuer:
CN=WoSign Class 2 Code Signing CA G2, O=WoSign CA Limited, C=CN

Serial number:
304E7576E2082A9B6E87C0FFCC4B397C

File PE Metadata
Compilation timestamp:
7/16/2015 3:24:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:wxGtOnSFvdGsIPJP2HbjuD9VNydnxcMT93ozUHkqKRejZp0DIGbCHoJrfRaBW:VUSFFCPJP2HbjuD9nBxgKRwKMGeMRao

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 34, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 1E, D8, FF, FF, E8, 6D, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 33, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 54, 86...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file anytogif_setup_ad.exe has been seen being distributed by the following 21 URLs.

http://www.softonic.com/sads/tracker.php?ev=c&co=AR&sid=345af67db03f36d3fe2c729242e7fd4a&upv=48c3b465fe209f23bb2c561ef8ed8e39&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F2B4DF1BFC96A568E3F48CAAC0E47F2F99C382FCF8E23069F5B742DCA1129F2ACA865A2C6EBAB2882D9E8754D0CA4030CB2624CA83B513D7D9C1387C962C77F650D0B96203F46A6C4ACB241BB4FDD4CB4CE95EFCC6B705BC9DCBEC45E936ACBA3254CA44B87A7022BCC06AD5EC70D93AD3435DB369A1B4A580338442B67D2C441E&h=611D5C80F7868A8B789F152AB5054D9D120171D016792161D2CA7D82E61DE329&directdownload=1&f=69667320&d=http://en.zxt2007.com/.../anytogif_setup_ad.exe

http://fr.softonic.com/sads/tracker.php?ev=c&co=RU&sid=3a0998788018ed0a7be13c2860ec8f40&upv=ad1d9827c04156c916763df29c30f187&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA6CC51E5F2F1CC0781D87EC9BB0C214C631E233541EE5EDA1BB5B7AFF02804CBEB4F813F1EF4B82168CF71F73933711E64FF24A5C4D117721489DE194EFC310DB4942DEB63A44CB32E17724091B668DD23190162084F2F1BA7BD0FEC15D2628E69CE7D8D51A0E002C6AF84C64FD42A4FAF947184F616E88EEC70256936317E25FA92EB2EE4C635B0407608B68D36BC9D1BE3FABC7D6BD4D208508FD5EDF6E5E44&h=F401CDD042F67DE0996F34D3E2B6E9B2F7D7DB58BD4EA9FC24009D8DEC9F3D9D&directdownload=1&f=69667320&d=http://en.zxt2007.com/.../anytogif_setup_ad.exe

http://en.softonic.com/sads/tracker.php?ev=c&co=ID&sid=07fc0115a383f3500c17c437e39fe7bb&upv=1bba95703a95015722916ceeb16af637&z=results&sk=0&abp=0&params=F39B2A32BFC101987B1458170C278E0313858C8F8C1052086E0A941149460CE7510D1990FA7950706077490C398CB5F85408B25BF9D1F77252202DECDB7EDFC9CBEE07C46FDB90F53CE2A0934C77300EE590F70C61D8B809E48B4B6F7DA13CDE6AA93487EF278EB65313901CCA4A4E6B67E210A278AEB5B0CC4E1B91228349076CBE135F3537D3FBC84F5E4BA5790C050890DD772C310F4E5F64430F573F9A9B&h=FA14CAC01D82AAE41249B43B0D05D20449E8C61486A1AB26C32031C0B420EB9C&directdownload=1&f=69667320&d=http://en.zxt2007.com/.../anytogif_setup_ad.exe

http://de.softonic.com/sads/tracker.php?ev=c&co=AT&sid=1229fa2ff8bc64b2cea59242e6347ad2&upv=cc568b03a247bcf5829cc2a70199f225&z=results&sk=0&abp=0&params=E58A21D548552342230FD9D405D3DC9DBF0100912393E5E5A847434D03018F522A92461DFC32B1BF56401CAD7AE53DA1E81D7C7376479C1991EF9832B560E7419435F4C34815246D1C4F6A8465BDD5A2B5B4911958AAC43208EC8723908F21944E4340A9DDC61555862C2590C0F54BFA218B4E2B6A792223175E2DFA636C77DE7DE7E40D55013DC1B0400E2D97A1386584A249382194D5E51032D4CBC59AFEF075B0D89748480D735886CD41E8F6603B&h=3A696A968CAF878F766142C8FA6D886671EC7D9C90417BEBCFE50CD53C80200D&directdownload=1&f=69667320&d=http://en.zxt2007.com/.../anytogif_setup_ad.exe

http://fr.softonic.com/sads/tracker.php?ev=c&co=PL&sid=a8b5d669262fe9ec1b3c0b8babd39ed3&upv=3d292cc13e56e525e1bf104341dadd6b&z=results&sk=0&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBA6CC51E5F2F1CC0781D87EC9BB0C214C631E233541EE5EDA1BB5B7AFF02804CBE48137A983858851D2D259B94996A01B3ABBEBA48BA20ED5DDCE58C22570A1C86EB15FB6D983706331DADF9FC217B73878DEEC302DBB5FAB9EA81E13BAB7E14F6B3B93CD007E52905DCFF38B80753D2841F844A21D955E03580226FE8CE2FE9F11CF1383EFED3E198118A90E60E169133&h=D198A525BF16307390AB70B494E097FF24B9F162CCADFC731555FD80F80D8E40&directdownload=1&f=69667320&d=http://en.zxt2007.com/.../anytogif_setup_ad.exe

http://en.softonic.com/sads/tracker.php?ev=c&co=PT&sid=c1ca25ae4af523a0e0e39e87efb3a4f4&upv=fcf1d8226d9c2447dd30604ed60ef5c6&z=results&sk=0&abp=0&params=F39B2A32BFC101987B1458170C278E0313858C8F8C1052086E0A941149460CE7510D1990FA7950706077490C398CB5F840F91E8227B5ED8C5951617D0B35929A4A0D77E8D543DDF4BF1A36FBBDB076AEF5D6F23540E3CC10807C8DF7B257C2642200F32FFDD153FB80F854629A252C926C52AE1ECE94B5A8A4048DD17D8C348C08232A25E341C2F4D936218E7A2168C99F0928911DC58A5BAD137013B917A9B5575DCB8126C7E8BBF222674963A5F42E&h=601804829198DC9ABBF4532C1563719FC2CA02B6077BC252755F571C869C453B&directdownload=1&f=69667320&d=http://en.zxt2007.com/.../anytogif_setup_ad.exe

http://en.softonic.com/sads/tracker.php?ev=c&co=ID&sid=b4a6e31361a1767d1aed67b41f7e08ed&upv=3856f0af6ea9fe09bcf4070e7fdc9a4e&z=results&sk=0&abp=0&params=F39B2A32BFC101987B1458170C278E0313858C8F8C1052086E0A941149460CE7510D1990FA7950706077490C398CB5F8B3D4AAC05F7D24A981867E7490A194E194AEEB451818E12740461F3E0DC5FC983D800DAE41BA27770E293BBE0CE9C0F8B0FA5BB2EBC36CB5BCCF90313153EC105C7C319CAF075B5A423026B82DDB8F8951935AC1B66C502259065FB20A55F3E9BB47AABA90092E89E06A1F0A0473FF9B3F4E1A71FB24D3CC79B947C15FA17E4A&h=E76E6F55BC328405518F5D3B35EFA5B8DA18EE6140F5A91E43DC3E5839F7F612&directdownload=1&f=69667320&d=http://en.zxt2007.com/.../anytogif_setup_ad.exe

Remove anytogif_setup_ad.exe - Powered by Reason Core Security