softonicdownloader_para_windows-defender.exe

The application softonicdownloader_para_windows-defender.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from windows-defender.softonic.com.
MD5:
457f19be81e0c79a4e0e6e454e1cab52

SHA-1:
8ac7ab6f62d78bca517bff535b28cbdf494d1fd2

SHA-256:
3a0dd92a971ba99131696e4b21e13df4608385f6e2a1504d501c735a112deab5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/18/2024 11:17:30 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softonic.Bundler.Meta (L)
16.6.3.11

File size:
376.5 KB (385,494 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\softonicdownloader_para_windows-defender.exe

File PE Metadata
Compilation timestamp:
4/23/2014 9:21:29 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:VZ99w9e/wB+TRTsOJbSTBfSD+XrCW9ZXeRLTBZLpGImcyZItGY0YeYoSZzeK0ZJ4:VZ99wWh1s2WXOWXXGUImcyGm6oSZ98K

Entry address:
0x52DD40

Entry point:
08, 43, 09, C7, 8B, 4C, 24, 38, 89, F0, C1, E8, 0B, 66, 8B, 91, B0, 01, 00, 00, 0F, B7, CA, 0F, AF, C1, 39, C7, 73, 23, 89, C6, B8, 00, 08, 00, 00, 29, C8, 8B, 6C, 24, 38, C1, F8, 05, 8D, 04, 02, 66, 89, 85, B0, 01, 00, 00, 8B, 44, 24, 58, E9, A0, 00, 00, 00, 89, F1, 29, C7, 29, C1, 89, D0, 66, C1, E8, 05, 66, 29, C2, 8B, 44, 24, 38, 81, F9, FF, FF, FF, 00, 66, 89, 90, B0, 01, 00, 00, 77, 16, 3B, 5C, 24, 4C, 0F, 84, A1, 04, 00, 00, 0F, B6, 03, C1, E7, 08, C1, E1, 08, 43, 09, C7, 8B, 74, 24, 38, 89, C8, C1...
 
[+]

Entropy:
7.9630  (probably packed)

Code size:
336 KB (344,064 bytes)

The file softonicdownloader_para_windows-defender.exe has been seen being distributed by the following URL.

Remove softonicdownloader_para_windows-defender.exe - Powered by Reason Core Security