softonicdownloader_for_bluestacks-app-player.exe

Softonic Downloader

Softonic

The application softonicdownloader_for_bluestacks-app-player.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Softonic Downloader installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from bluestacks-app-player.ar.softonic.com.
Publisher:
Softonic

Product:
Softonic Downloader

Version:
1, 40, 1, 0

MD5:
93222df91c426d431b8b62f57127aff3

SHA-1:
0476056dfec2a5d71c9989278194cff704b11909

SHA-256:
92f8c9ed45eb9b05ee8260b4ba256549622b093e043adb14737dbcf93c5f0eb5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/25/2024 7:55:07 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softonic.Bundler (L)
16.8.5.21

File size:
465.1 KB (476,312 bytes)

Product version:
1, 40, 1, 0

Copyright:
Copyright (C) 2013

Original file name:
SoftonicDownloader.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softonic Downloader

Language:
Spanish (Spain, International Sort)

Common path:
C:\users\{user}\downloads\softonicdownloader_for_bluestacks-app-player.exe

File PE Metadata
Compilation timestamp:
11/12/2013 11:47:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:YTHiFlkI9s6dRi7X4+C9rr5TLeqvkQzoSNri4nKmNgZ:YTHEkBORij4+yrrlL+ML3y

Entry address:
0x15F630

Entry point:
60, 3B, F2, 76, 02, 87, D2, 0F, AF, CE, 0F, CB, F7, DD, C7, C6, 0B, EE, 8C, 46, 23, D3, B6, 1D, C6, C2, E5, 8D, 0D, E3, D7, 00, 00, 02, E5, 81, C1, 59, 07, 00, 00, 84, E9, 84, DE, 24, 8F, 50, 68, AC, 2D, E1, 00, 81, FB, 86, D2, 00, 00, 77, 06, 69, F9, 00, 90, E7, 8C, BF, 6D, 9B, 08, F1, 8D, 3D, 13, 78, 1D, 91, 81, ED, 3D, 88, 8B, 81, E8, 00, 00, 00, 00, 5F, D0, EC, C7, C1, 88, 0B, 49, FA, C7, C0, 4A, 5B, 04, DE, 81, FE, ED, 89, 00, 00, 78, 02, F7, D9, 0F, BD, D8, F7, D8, F6, C2, 85, 20, EE, F3, 84, C9, 0F...
 
[+]

Entropy:
7.9717  (probably packed)

Code size:
352 KB (360,448 bytes)

The file softonicdownloader_for_bluestacks-app-player.exe has been seen being distributed by the following URL.