pf7-setup-en-7.2.1.exe

The application pf7-setup-en-7.2.1.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Scriptable Install System installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from photofiltre.softonic.com.
MD5:
53e236473695c1bf0fdfeeffb9de39aa

SHA-1:
37273c9c8c01f00475d9d03ad7dc622c165704e4

SHA-256:
dd879138f4347d1fa9de4a89b5997ccd0128e89d6f3ee23969a71f3fd3e4a6f1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/16/2024 5:26:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bundler (M)
16.11.30.12

File size:
5.1 MB (5,317,636 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\pf7-setup-en-7.2.1.exe

File PE Metadata
Compilation timestamp:
6/6/2009 11:41:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:Q1dUyT4TPwTNJV057N+rU58dFK67niNqOcAtu5x4AUjOqstY9sqbIKVQoLU9:Q1dZETYjJAPeAtu5ECgb/yoLM

Entry address:
0x30CB

Entry point:
8B, DD, B4, EA, 8A, DB, BF, C0, C5, B8, 16, 0F, B7, D8, F2, 80, EB, 56, 8B, EE, 49, 69, C5, 2F, 5C, 57, 6F, 81, EE, 29, C0, 00, 00, 0F, AF, D9, F3, B3, CD, 81, EE, 3C, 0A, 00, 00, F6, C4, 88, 86, C5, F3, C7, C7, 1B, 69, 6F, 30, 69, DB, F1, 50, E7, 21, 8B, F8, 0F, AF, FB, E8, 21, 00, 00, 00, C6, C2, 1B, 69, E9, 77, AB, EB, 35, 8B, C6, 3B, D7, 84, C9, 11, C7, C7, C1, 97, 73, 78, 95, 88, CD, B2, 40, 81, FE, 99, 7F, 00, 00, 5B, 85, FA, 71, 0F, 8D, 2D, 18, 08, D6, 43, 80, F8, 60, 69, C0, 60, F4, 1F, 5B, 68, D3...
 
[+]

Code size:
22.5 KB (23,040 bytes)

The file pf7-setup-en-7.2.1.exe has been seen being distributed by the following URL.

Remove pf7-setup-en-7.2.1.exe - Powered by Reason Core Security