haihaisoft-universal-player-es.exe

Haihaisoft Limited

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Haihaisoft Limited  (signed and verified)

MD5:
13af80e7df92c160794f627f5ca33f88

SHA-1:
4e31408623578727537bd891bca090a85d5a611e

SHA-256:
eff6725ac7e779791025ba99c7df94e361b2dfa1c4846f228b0b267fa223226b

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/18/2024 1:56:05 AM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
Suspicious_GEN.F47V0628
7.2.269

Zillya! Antivirus
StaticHeur1.Win32.18
2.0.0.1927

File size:
17.5 MB (18,358,776 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/6/2010 6:52:59 PM

Valid to:
1/6/2013 6:52:57 PM

Subject:
E=joseph@haihaisoft.com, CN=Haihaisoft Limited, O=Haihaisoft Limited, L=Hong Kong, S=Hong Kong, C=HK

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012606708FBB

File PE Metadata
Compilation timestamp:
11/21/2007 10:25:22 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
393216:SxbJNptUQd6H1hw88KqAuqZyKmwHrrT8ZtGvAw0/pWkfsu+QYOlw7ZB:SxHptjKhJM/H0LcpWkfc4wB

Entry address:
0x3512

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, DB, 5E, 89, 5C, 24, 18, C7, 44, 24, 10, A8, 85, 40, 00, 89, 5C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 53, FF, 15, B0, 82, 40, 00, 6A, 08, A3, F8, A5, 42, 00, E8, 0D, 26, 00, 00, 53, 68, B4, 02, 00, 00, A3, 00, A5, 42, 00, 8D, 44, 24, 38, 50, 53, 68, EC, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, D4, 86, 40, 00, 68, 00, 95, 42, 00, E8, DD, 24, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, 00, 50, 43, 00, 57, E8, CB, 24, 00, 00...
 
[+]

Entropy:
7.9999

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file haihaisoft-universal-player-es.exe has been seen being distributed by the following 32 URLs.

http://gsf-cf.softonic.com/4e3/140/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=71879&instance=softonic_es&type=PROGRAM&Expires=1445439165&Signature=DOsyR4zf~aY4aKxIg6J2RBPQDt~ZVnVj-HQO1RPVvTGJrIfLhgXkcBpaLXLhhsWH9KCTREcel6QeeR2pN93AXAk66bxP1HghyE0XbAtl5Y825SjApOA78pD-9IqMS4H~EFZzJjOjKhJGj1GW-FBy1ERM2Rek9XroEdg4Fg4bMpA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Haihaisoft-Universal-Player-ES.exe

https://dw.uptodown.com/dwn/pSPLPpHsHkaq4MnAMCmEY847YSdWKQLkUXyKRSE-ouXPMZ1bIvcfc9-qsPlr-LJspdktHOScVC0aLkZ1_CEYKmipkqYnc-xqk7ZcHXPvpbFyIttklKQ5ONrnqyzugwGR/IkuJ5gpYa2BRtkh0kc-28l7AHzWHQT7asoargJ-Rubjhr_IbONc1cK-YXiOO7xpKdFeCnq0pDnyPNjHLAdcTQkqhygk_OI3DP0NdErNwIRMA3TF23dAbHv4x-_vBnmKm/NzHGeXLjv4nNoIjJnPLNYTAoeitjj6hBV8lEfq7t87w2Xwsq6Xp3EtWtfZR2qIHbO5mbjrlOiPcXPWIDz0H7j6y_S_h9fgpeHFWC-jk0lYPUya7eC8YzYtwOXL_N1NN5/.../

http://gsf-cf.softonic.com/4e3/140/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=71879&instance=softonic_es&type=PROGRAM&Expires=1477653884&Signature=MydeFDnGeTtFskwyzbSQCaJVytpKhkNxLeDcHvsrvgzZisiMW6rrjCtK0mFoa39FgBRSpNH3Rs9Tq3aRRwSBMMFEpZilog-zoTiniKIfky-Boq0R7CBG2QjhWTlDoLxR8kYmf2fWgO~V8X1l4eC~X6SN4nrr1J0VjELbFh2~bhg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Haihaisoft-Universal-Player-ES.exe

http://gsf-cf.softonic.com/4e3/140/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=71879&instance=softonic_es&type=PROGRAM&Expires=1473004945&Signature=KAr9ssuHjARPlMMagXCGYzBUvoP4fGjUeWVSA8Y3OW5cO7Ow4hp023~O9B6RGvBfhpchYFEJKiKq7cXDt~FIHVRJd-gjK5Gwgy4A1g07FhYikw6AJ9QhtgABrXplRfpNvUAPJqXoGM3k41kKTb~ltDC8C12yZgJ84Gow-UwJDak_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Haihaisoft-Universal-Player-ES.exe

http://gsf-cf.softonic.com/4e3/140/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=71879&instance=softonic_es&type=PROGRAM&Expires=1476568823&Signature=LLm2HeBPuGrK5rtynjRika9VwD5-sNCOeb-oEunI3~Rvn7nDoUVOE4djqAAPJ4A6NFtf8ol2P1q1PzXOy59RdQ8RwPNd9d1RhzhizDo2wJIwFUYikb1B3bYGlxhSezigVC4idMOw~9KFdAe6wFZVEoqhcdYlXztzSDg~CQNdGG4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Haihaisoft-Universal-Player-ES.exe

http://gsf-cf.softonic.com/4e3/140/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=71879&instance=softonic_es&type=PROGRAM&Expires=1478378647&Signature=RCKxZ8xbindgYGZ-3zyGazqkeQUhn5fG1BJa-8TAmWnrw-mxhm-uBubUzbc7wU3wp0uuTQC4tc6Bs8ZrD8e6sPgmu20zY~1-fKHPrVoJYHMKwlS6Q02Y0UORhMH0R1r94m6cyaX8i8X0vlaJRQVuVLearKiP7xrywbzOLd~RdVY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Haihaisoft-Universal-Player-ES.exe

http://gsf-cf.softonic.com/4e3/140/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=71879&instance=softonic_es&type=PROGRAM&Expires=1480113635&Signature=NP93nADpepBinW~Xl5XuUqngOiuAGnHtAUyUIL55vaB0VG7wokmawnWkVdjO34LCzFFbmZbtoxnaYwv5rl9sbgQOaIIhVCmcuJph0jc1nlmPJzOnorgS~IZpWzUo~QEpWk1AxkE3kYN1AbjBx5vmhjUGARXz~PA7PKGg4Ro17Dk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Haihaisoft-Universal-Player-ES.exe

http://gsf-cf.softonic.com/4e3/140/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=71879&instance=softonic_es&type=PROGRAM&Expires=1476456745&Signature=UEcmnrJOu6QC02Lt875jQCOtyZYH5qxiBIMzjPImLEeTuZXFrqvsjaNdNlfkb8oT62jmPxlkg4E6QkhMhq8-8Za8oCn-wo2fdmzDisiV0WGjll3u6DlcBb~mg91oSM50uI~-xkpzDvw9f8-9-go6HsREnVpcWXfeK61ZqDrif7I_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Haihaisoft-Universal-Player-ES.exe

http://gsf-cf.softonic.com/4e3/140/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=71879&instance=softonic_es&type=PROGRAM&Expires=1480498634&Signature=aCOhu8dDjZ1-OUgyazQcUJC~TZ96n4A9uC7O9khE2m0vK6KZK0Kg2JcLgsb1OTjEn8Mc412QjOQvJ9v4F3VxK1s74g6qScU74yfZU6MiDeXE9g4ECWdCg5B5bVJNfKBP8xRTcuvuL-wcwvITF1LDj1g0WW8q36ye-w6A4NVy0rw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Haihaisoft-Universal-Player-ES.exe

http://gsf-cf.softonic.com/4e3/140/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=71879&instance=softonic_es&type=PROGRAM&Expires=1467380743&Signature=ZGOPlcn3Otae6PaH25hgdl8tK2~JcJFFM6tIs1MeIMWvlLGR~HBNUkW7JkHoQX2ooUHhieTf74qpTITO~salP4snFGXBi5R82CO4rYhYxvlDLsaSGpm3Q8jknDNedu0HVK1P56Cu1LUfY0U3caYkY-m-EasNLFlHFd-0CKnlIdc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Haihaisoft-Universal-Player-ES.exe

http://gsf-cf.softonic.com/4e3/140/.../file?SD_used=0&channel=WEB&fdh=yes&id_file=71879&instance=softonic_es&type=PROGRAM&Expires=1471168934&Signature=TKMBTesO5PONVk~KRhxmI4HpdYiGUYXWyTAS54v4rgCa5Xq4oJj0yfKAFcbdeuVkYNtrunNDGn8l1vNbWBVmRI0fskslh8kuoZs9mR-R1TSN6Z0XbKRVYd-NGSsEIZ~V7iMJ3wODwDDCxddV5eR3DXsqSs9hHGIoCbZKU-OWm2k_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Haihaisoft-Universal-Player-ES.exe

Latest 30 of 32 download URLs

Scan haihaisoft-universal-player-es.exe - Powered by Reason Core Security