sosintwr.exe

Steganos Online Shield

Steganos Software GmbH

This is a setup program which is used to install the application. The file has been seen being downloaded from www.segurisoft.es and multiple other hosts.
Publisher:
Steganos Software GmbH  (signed and verified)

Product:
Steganos Online Shield

Version:
1.4.14 Rev 11225

MD5:
533c452dbe2f47152fad89d281ff1ebd

SHA-1:
be9f33b2f2564c76b721d9a0a7f7af1ed758a41b

SHA-256:
4f6405ca258d4cd77bec6df9b1821c107a499b9b7cb39b0ce1e45028e8a99763

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/18/2024 7:49:17 PM UTC  (today)

Scan engine
Detection
Engine version

NANO AntiVirus
Riskware.Nsis.Adware.dqabed
0.30.24.2086

Zillya! Antivirus
Adware.Steganos.Win32.1
2.0.0.2591

File size:
39.1 MB (40,947,936 bytes)

Product version:
1.4.14 Rev 11225

Copyright:
Copyright (c) 2015 Steganos Software GmbH

Original file name:
setupwrapper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\sosintwr.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/10/2014 7:10:01 AM

Valid to:
11/3/2017 8:55:47 AM

Subject:
E=certificates@steganos.com, CN=Steganos Software GmbH, O=Steganos Software GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112127389AB528A3A8EC995621C824069818

File PE Metadata
Compilation timestamp:
2/23/2015 6:10:14 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:A1h99G2l8YXQ3wKSigqn51IIjeF/uyb86FPKNR6Im9gRMA60Z/Rp1dLMv:iBef551JHGPbeMA6ORp1dLu

Entry address:
0x10BF6

Entry point:
E8, 3F, 8B, 00, 00, E9, A4, FE, FF, FF, 6A, 0C, 68, 90, 86, 42, 00, E8, A0, 44, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, C8, C5, 42, 00, 03, 75, 43, 6A, 04, E8, 29, 8D, 00, 00, 59, 83, 65, FC, 00, 56, E8, 51, 8D, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, 72, 8D, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, 15, 8C, 00, 00, 59, C3, 56, 6A, 00, FF, 35, F4, C2, 42, 00, FF, 15, 74, 40, 42, 00, 85, C0, 75, 16, E8, 2E, 28, 00...
 
[+]

Code size:
139.5 KB (142,848 bytes)

The file sosintwr.exe has been seen being distributed by the following 13 URLs.

http://www.segurisoft.es/software/Dwl_portalsa/.../sosintwr.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=PE&sid=83ab235fb9a5fb5c504bfa81dae8759b&upv=e0d97bc100a9d3338c73b2f64d24dfa8&z=download-cpd&sk=3143&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F26BD8E26C5D6F4F4776204997EBA3AEEACB39829447002032987B9E72DDC327B941E32618F899B357F19A2333AFF2C2B75AEDE52A51F4E0CB8724DEDC93887A36B3E2F882C4D215AA8FC4831EE615AE4D23295C894F1B3DA3B5ACB693FCE789E930F016ADFB0DD066FDC8146C29A3F2695916054E423F5CF7C54FEC9B94AA690A&h=E85393B9A87A33451615AD351FC13CED18FB5BE8416748D7A6652B021116EC5E&directdownload=1&f=69687091&d=http://www.segurisoft.es/software/Dwl_portalsa/.../sosintwr.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=MX&sid=4de557737ad76f00ab7f099bbecb81e5&upv=3cf7c157873e7d4a870c4a07485e68b8&z=list&sk=3130&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F2DAB019A2D5A8EA1C17ADDAE5C4F9D20234223C1283CBB83C37918D214670436A665B44662B5E7DF3032FEBA77560EBBD007B5C5B8D4EEBBCA0FE04C9CC7254A431B4C61FC87C1DFCDED42D457E1D41FB17DAA196F72EA2FA25DB4AEFCCB98358E20B2821F7F9A007EF63008D8E6016FD5C9F371A170D667445AF7BAB0EF095F3&h=6241E52FD9E24206929B0B9F44358F790D1CB8F807E4C1CC54E703C81A1C1499&directdownload=1&f=69687091&d=http://www.segurisoft.es/software/Dwl_portalsa/.../sosintwr.exe

http://steganos-online-shield-vpn.softonic.com/descargar

http://www.softonic.com/sads/tracker.php?ev=c&co=CO&sid=aabfb75cd459fb768501fafb937b3ff4&upv=bc697ccba551e43f9db6abf1d29346d4&z=download-cpd&sk=3144&abp=0&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F26BD8E26C5D6F4F4776204997EBA3AEEACB39829447002032987B9E72DDC327B941E32618F899B357F19A2333AFF2C2B75AEDE52A51F4E0CB8724DEDC93887A36BA989FF20F7A47D32DE7B2F6CAF5A04DF495791EA1C01DD4A8F96D2D0A7C581281650A871137399CFA2C4614002830929DD6D62DA5247E73B535E5C12DCA007E&h=EECE67F022472CD4A08288C29AD2EBB3C3EC21C3E14B084E1C155223A7F87FF3&directdownload=1&f=69687091&d=http://www.segurisoft.es/software/Dwl_portalsa/.../sosintwr.exe

Scan sosintwr.exe - Powered by Reason Core Security