SoftangoDownloader_Firefox80a2Aurora70b6Beta62Final.exe

Softango Technology LLC

This is the Performersoft setup installer. The application SoftangoDownloader_Firefox80a2Aurora70b6Beta62Final.exe by Softango Technology has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the InstallBrain installer. The setup program bundles additional offers, mostly adware, using the InstallBrain installer, a pay-per-install monetization download manager. InstallBrain will also install a background updater service that will update any installed browser add-ons and plug-ins. The installer is marketed through download protals and search ads as the free Mozilla Firefox web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Softango Technology LLC  (signed and verified)

Version:
14.9.8.16

MD5:
22e1a822c426d46007eab2f500097b5d

SHA-1:
0435b6e689fb9f39d00929ef9380628364496b9c

SHA-256:
7eb790748d5964e9888952bb905fbc3b9e1117c588bf30857e05f685aae4055b

Scanner detections:
21 / 68

Status:
Adware

Explanation:
Uses the InstallBrain monetization platform from iBario to deliver bundled adware both search toolbars and PC optimizers from Performersoft.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/18/2024 7:26:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.InstallBrain.E
873

AhnLab V3 Security
PUP/Win32.InstallBrain
2014.09.15

Avira AntiVirus
ADWARE/InstallBrain.Gen
7.11.172.30

AVG
InstallBrain
2015.0.3351

Bitdefender
Adware.InstallBrain.E
1.0.20.1290

Dr.Web
Trojan.Packed.28512
9.0.1.0258

Emsisoft Anti-Malware
Adware.InstallBrain
8.14.09.15.09

ESET NOD32
Win32/InstallBrain.CN (variant)
8.10419

F-Prot
W32/A-3442f84d
v6.4.7.1.166

F-Secure
Adware.InstallBrain.E
11.2014-15-09_2

G Data
Adware.InstallBrain
14.9.24

herdProtect (fuzzy)
2014.11.14.2

IKARUS anti.virus
PUA.InstallBrain
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.183.13358

Malwarebytes
PUP.Optional.Softango.A
v2014.09.15.09

MicroWorld eScan
Adware.InstallBrain.E
15.0.0.774

NANO AntiVirus
Trojan.Win32.InstallBrain.derzsq
0.28.2.61942

nProtect
Adware.InstallBrain.E
14.09.15.01

Panda Antivirus
Trj/Genetic.gen
14.09.15.09

Reason Heuristics
PUP.SoftangoTechnology.t
14.9.15.8

Vba32 AntiVirus
AdWare.BrainInst
3.12.26.3

File size:
1.2 MB (1,309,040 bytes)

Product version:
14.9.8.16

Copyright:
Copyright 2014

Original file name:
SoftangoDownloader_Firefox80a2Aurora70b6Beta62Final.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallBrain

Language:
English (United States)

Common path:
C:\users\{user}\downloads\softangodownloader_firefox80a2aurora70b6beta62final.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/19/2013 12:14:11 AM

Valid to:
12/19/2016 12:14:11 AM

Subject:
CN=Softango Technology LLC, O=Softango Technology LLC, L=Beaverton, S=Oregon, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
277EA1EB753393

File PE Metadata
Compilation timestamp:
8/20/2014 11:24:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:r1QfopqgXiXi6kgaINVD4W7CS7YsXDV6YkHzr9jWp04OY3erxGOjbvD/+XbdeXcq:r1wgSXiTcNV7CS7bkY8xWa4OYyDmXbdk

Entry address:
0x1A81F

Entry point:
E8, 30, 6D, FF, FF, E9, 2B, 9D, FE, FF, C7, 01, 64, B5, 41, 00, E9, B8, 64, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, 64, B5, 41, 00, E8, A5, 64, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 69, 20, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, 51, 10, 56, 8B, 32, 8D, 41, 48, 3B, F0, 74, 12, 89, 71, 3C, 8B, 71, 30, 8B, 36, 57, 8B, 79, 20, 03, 37, 5F, 89, 71, 40, 89, 02, 8B, 51, 20, 89, 02, 8B, D1, 2B, D0, 8B, 41, 30, 83, C2, 49, 89, 10, 5E, C3, B8, 60, 3A, 42, 00, C3, C7, 45, FC, FF, FF, FF, FF, B8, F6, 2F...
 
[+]

Entropy:
7.5243

Code size:
102.5 KB (104,960 bytes)