softinfo.exe

Software Informer

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Software Informer’.
Product:
Software Informer

Version:
0, 9, 163, 0

MD5:
85853cf2db633757aa188b924939e957

SHA-1:
a1164972e7ea63aa007c435529b60478fa29bbd7

SHA-256:
fb0e1a49c1cf63a81e5c594d521e4a07438d2cf97c95ebc6da3e0580b800ecbf

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/26/2024 10:13:11 AM UTC  (today)

Scan engine
Detection
Engine version

Panda Antivirus
Suspicious file
14.04.10.06

Prevx
Heuristic: Suspicious Mailer
3.0.4

File size:
688.1 KB (704,592 bytes)

Product version:
0.9 BETA

Copyright:
Copyright (c) Informer Technologies, Inc., 2008

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\free download manager\softinfo.exe

File PE Metadata
Compilation timestamp:
4/1/2008 3:10:34 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:dR//urUkTxITuAnLunniqzOHgoy5JK8WTa6q9fjAAPiX:TTkTxIT5nLuiqQByWfTaJjAAPiX

Entry address:
0x549FA

Entry point:
55, 8B, EC, 6A, FF, 68, 20, 31, 46, 00, 68, 5E, 4B, 45, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, F8, C7, 45, 00, 59, 83, 0D, 00, 25, 47, 00, FF, 83, 0D, 04, 25, 47, 00, FF, FF, 15, F4, C7, 45, 00, 8B, 0D, E4, 24, 47, 00, 89, 08, FF, 15, F0, C7, 45, 00, 8B, 0D, E0, 24, 47, 00, 89, 08, A1, EC, C7, 45, 00, 8B, 00, A3, FC, 24, 47, 00, E8, 40, 01, 00, 00, 39, 1D, D0, 1C, 47, 00, 75, 0C, 68, A6, 4B, 45, 00, FF, 15, E8, C7...
 
[+]

Entropy:
6.2378

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
364 KB (372,736 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Software Informer

Command:
"C:\Program Files\free download manager\softinfo.exe" -autorun


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to mailerdaemon.software.informer.com  (208.43.5.68:80)

Scan softinfo.exe - Powered by Reason Core Security