rsload.net.ffsetup3.7.0.1.exe

Format Factory

chen jun hao

The application rsload.net.ffsetup3.7.0.1.exe, “Format Factory Video/Audio/Picture Converter” by chen jun hao has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from lb.cdn.m6web.fr and multiple other hosts. While running, it connects to the Internet address server-52-84-203-181.tpe50.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
Free Time  (signed by chen jun hao)

Product:
Format Factory

Description:
Format Factory Video/Audio/Picture Converter

Version:
3.7.0.1

MD5:
032eece7e7e3e594ea9440c1f00f5a1d

SHA-1:
9c1e3dbd24389b3e160213d81d4f027a383c082b

SHA-256:
3d516eeb5454e29845fc3d17a6adfe50a994fae6a743abd0f970b673d21685ff

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 2:53:38 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.chenjunhao.Installer (M)
15.8.25.13

File size:
51.1 MB (53,579,016 bytes)

Product version:
3.7.0.1

Copyright:
Free Time

Trademarks:
Format Factory Application is a trademark of FreeTime

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\rsload.net.ffsetup3.7.0.1.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/25/2013 12:09:13 PM

Valid to:
6/25/2016 12:09:13 PM

Subject:
CN=chen jun hao, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215F9DDE67138EA8C52C9F6F1901954DE8

File PE Metadata
Compilation timestamp:
12/17/2013 8:46:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
1572864:R/laAXFAvNTXxcSqtwLWxjxymWqIErzuuoPKV:RNnGvZSSqeLW1xymWDcboiV

Entry address:
0x3A0A

Entry point:
81, EC, D8, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, DB, 5E, 89, 5C, 24, 18, C7, 44, 24, 10, 40, A2, 40, 00, 89, 5C, 24, 14, FF, 15, 90, 90, 40, 00, 89, 44, 24, 1C, FF, 15, 34, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 90, 40, 00, 53, FF, 15, 30, 93, 40, 00, 6A, 08, A3, B8, 3E, 47, 00, E8, 2B, 2A, 00, 00, 53, 68, B4, 02, 00, 00, A3, D0, 3D, 47, 00, 8D, 44, 24, 3C, 50, 53, 68, 84, A3, 40, 00, FF, 15, A4, 91, 40, 00, 68, 6C, A3, 40, 00, 68, C0, BD, 46, 00, E8, 0D, 27, 00, 00, FF, 15, B4, 90, 40, 00, 50, BF...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
30.5 KB (31,232 bytes)

The file rsload.net.ffsetup3.7.0.1.exe has been seen being distributed by the following 8 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-192-3-244.lhr5.r.cloudfront.net  (54.192.3.244:80)

TCP (HTTP):
Connects to server-54-192-129-96.ams50.r.cloudfront.net  (54.192.129.96:80)

TCP (HTTP):
Connects to server-52-85-33-131.mnl50.r.cloudfront.net  (52.85.33.131:80)

TCP (HTTP):
Connects to server-52-84-203-181.tpe50.r.cloudfront.net  (52.84.203.181:80)

Remove rsload.net.ffsetup3.7.0.1.exe - Powered by Reason Core Security