rfftrial.exe

RFF Electronics

This is a setup program which is used to install the application. The file has been seen being downloaded from rfflow.en.softonic.com and multiple other hosts.
Publisher:
RFF Electronics  (signed and verified)

MD5:
e1012cc4bc5aab82810bbf145504068d

SHA-1:
fa4df6e67d2ab4fc8e9107f197b262240f5fad58

SHA-256:
5e62eecd30e0315ed59f7b92d559b979c89cbe56b844f0e22c48ac99e58e1ccd

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
8/13/2025 7:41:29 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160503-1

File size:
5.3 MB (5,600,528 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\rfftrial.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
5/26/2016 10:53:38 PM

Valid to:
6/23/2018 2:50:11 AM

Subject:
CN=RFF Electronics, O=RFF Electronics, L=Loveland, S=Colorado, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00E6A50FEA1067BD92

File PE Metadata
Compilation timestamp:
11/3/2009 1:54:29 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:+dvNPsv5JZ4atjoFLE9Dw5fgd4V5RdV1blzH/B3B9I8ikqTmGQYtTPsI6pjNux5j:+dvpi3Z4aZju13RdNH/B3B+BmGQYxPsI

Entry address:
0x1479F

Entry point:
E8, 02, 67, 00, 00, E9, 17, FE, FF, FF, 3B, 0D, D8, C9, 42, 00, 75, 02, F3, C3, E9, 82, 67, 00, 00, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, 18, 48, 41, 00, 6A, 00, FF, 75, 0C, FF, 75, F8, FF, 75, 08, E8, 54, E6, 00, 00, 8B, 45, 0C, 8B, 40, 04, 83...
 
[+]

Entropy:
7.9902  (probably packed)

Code size:
144 KB (147,456 bytes)

The file rfftrial.exe has been seen being distributed by the following 3 URLs.

https://rfflow.en.softonic.com/.../6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAML0A4N mIT94MDqVFirEXhKrYZGp8juxJusGyoloiYwE7eppzzUotyTPVe H1QQRlbyAuraJgQNILnr0dGZJhi3fGLS40e5CzImtF0dNQY3oD8lspwAQJIubrF3izdIfY=

http://rfflow.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/trmsvRChbxdrflJq3ZIylWuZz/z9rjSQWPa0r2xNa1vsmtkimeFSd2uE4HIw355sU1XecjDX63/.../O6omySOGx3nQvf Aqd6Bpki8iVnMZIA5k=

Scan rfftrial.exe - Powered by Reason Core Security