suddenattackdownloaderv03.exe

Nexon America Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Nexon America Inc.  (signed and verified)

MD5:
40c58585e4049d9753a62548b914b092

SHA-1:
f1dfa883ac06d1fda1a1e6fa0edc2308f03bb1fa

SHA-256:
764bf3e5a48c4c3c6d5ba81d821c322f13e4371db90d4445dbea67a9ba2e0cf2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 1:08:38 PM UTC  (today)

File size:
1.9 MB (1,943,648 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\programs\suddenattackdownloaderv03.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
8/1/2011 3:00:00 AM

Valid to:
6/24/2012 2:59:59 AM

Subject:
CN=Nexon America Inc., O=Nexon America Inc., L=El Segundo, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
07A48D7788950DBCB750370501109B26

File PE Metadata
Compilation timestamp:
12/15/2011 8:37:36 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
24576:zKx+eI7y6/FRhKilq8RV00Ql1DyyeDITSEgoJsNQ+rSHJnS8du1LsVclQjLODcDz:zc+tzVVqCPQzWTEuEdIQeSpSpselQHO

Entry address:
0x6741B0

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8789  (probably packed)

Code size:
1.8 MB (1,871,872 bytes)

The file suddenattackdownloaderv03.exe has been seen being distributed by the following 46 URLs.

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_en&type=PROGRAM&Expires=1485824976&Signature=OIF0Rh-IlsEciE1gND0MRa5douzZEzhjdOx-TY0O7d4IaezmN4fk7cc8Ry7-cua89PEkCXigW8EwEIY3bkqKaBT~akn739I-vM8PgG56pcxNrZPJAgfeE6UJSsGFTnYNLiFWuoxpnVg66OZnlOprhTvvSc1Yumxxf4ri~UIYxb4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1479811660&Signature=P7a6OAFOrMZljGJbP1fHuD5C11sVBoDw~SNGvodDGWLYJm68uwGkkGjXEx88iAHQRb5lv~pIvuswKxUxP4~CcAO6f6pn9SPtIjZ7hYGHRqCpLuJYc881BL19C7bc0OK3G3QR2cbTjIq4SVhWLjsIqQ5qljqY2-YYtTHASxaScLY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_en&type=PROGRAM&Expires=1474678206&Signature=BkQr69zmAord1-diBjQc8UKE1ZYytXFz2nD0EX0SwvYVDxWT4mk7GZ4rJsy112wDnI7gTvPzTwHZRlXq3I9s8mLVBx61CF90e7lmuCakbXhVRPNW4xVHLwEAADUrgHfXwxZjY2dzBZIWunwU09Ozpakh2iQDu~bU0fdCuAj-pK0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1464946503&Signature=Axu0neEpa-Y34T1rQTdHRP420Z5nhQTCgy3-NsWBzHOfYn7xgQwo~1QUKEMn77LVdkgOPRtMrZC-dbivG2xqdBIK4aBJblgbVux-Domslg3akrPbjLfEAM2PaBAUP9y~SGkY2ZkjlqTrtshsFU8aM~JKX2LMhZaRSvrFuE83jn0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1466314506&Signature=SyMHqzrTNnW3LW2lS1FTA0Bn01CNl5LjrygwzyXrVHbcCPieSaJw1oAYBtDoDLaqS~FlrbLH5zc7HJKQwRGWA1ZWFtMqi880eeSYLtq0e6mBChOVOPxKxJ8ST6-2O7XQzFQUN33KdVGpoyhNvfihMooDZxNPG~Sftt8MwwxQeXY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1458880597&Signature=gRuL6k3uzFMkVVdrw1SFB4iuje2PMmTnnDCNhxVSfUHLfkACzlKPfcWla2qVtqzqNSGknyneh-jnlE6JEHQl8nHoEncwlue7dzFj66PP3EoAA7MNvfQr3P6j2yMCkoyZZRb~Oj6hU1lCBclkABObyRewa9Upqhw-XpyY9C2F6yk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1483095701&Signature=BIvxZ6kLFaChXUf1rwS6Az-LbeBaSpo6uS8frRuzj5BT7B2VnTCzMIvXcmn0PRWzvnr~TQaVGIFhwi5ysogDyICxRqh6UHkD6D4ChZM1-tvmYeB9xxY6nbZU4l~DppSsSCk6vkcw1JEWcWVPWYn35acp7qXBu3A2QqVmzFQU4sM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1454338338&Signature=S-RHDH~HDUw~8PYd7hC-XeCdsF-zOnRH-~AjVKU1OScRagf0F2GTcBCvLZZ2tMMTp~G5~5W~1BusW0Q-obir9Y2oTitkNvTeZHWxxJlVTHQBHsCh8QMFVL5iQcUuBXBx1h45eY~s~YiV7UBU-oDn419H9KF42iJZg5v4MDH5sLk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1470627975&Signature=aqJMRX3c0kAyPHPooT7FEqyM1U4LKN-3dXMrvVqtDV3xce6NGn0nff7qLA5kyhym5ku~Kaa2~G93u2iKO~BBlIEwnuKNxeeDPgr1Qj9MPiaF4RE6zabrryYWp2nvwb2BE-3ha0Bdw7YtDe9qDQqueDMcV48dwVvJp6ZyMsxk~0w_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1479140630&Signature=TtUjwFRnlbNQfhM2pyWU2SMGwaRJGoNRtXqTifRlWbkhgiRDWRVRkgdC38nbgKNvznBrVStVvlMwpkccok~0s9v22SX1nChzqS9yY5XSEr9POccqNHk4mJ6Im~UMh3tl0Fdg0Sxp1Aif06Z-d3nE55K8Zsjio2a39V7sd9-Wr7Y_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1478772738&Signature=W-97XeL5syM-OWF5J4j8RESMhL~rDAGcPdrmhMQ4cD4HeluERH6Timb2YT8ww9MSAWX1hVCCBh~4Mv-as-ZFWZ3NQwmJa8Ove8dpZU-37hEsV2jjP~WIs894fPk7HWTa9KVQPrg9lfr36zVjGpsNmdIWyf5vutNE0tnGkAM7M9M_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1477393541&Signature=gpq9viHFipYaIjtO96fqpkHbBlC7tbMWJXZzQldFbmSn7gwlSTEmpFChvh92~6rz0uPjV5bSuMkjvuFEeFq5-goB2MJKkSH7eF7pr4ovmOL7GzIxxvx0EeEk4cWJcHN24SV95UFSxoSqdv8CpUu9T5ZleWPCC-CI4Fy5N6g0WL0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://global-shared-files-lw.softonic.com/f1d/fa8/.../SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_en&type=PROGRAM&Expires=1478495627&Signature=DEqgLiOSVhH0iY5OXUHDv1Zqwqhst4kzOt-eNVTJS~mZXG-MS-Nei51tlPtlWMv-Z4Gjlv8zgwr-RQwSmUdrrNhX4kuGoO0XDcECt62A9iWPAhSMqJTmj8EJ3Z39cIWZw89rCUyB-gUG7qdoMsgbdDAyomSftpW3H8o4MiQg2RI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_en&type=PROGRAM&Expires=1452855650&Signature=BII~v-2sxnQdV4HguhTs0VuxfCye54RP1FBayC~0n75tc0pUdcLMTgjBgSIzSA~eLtXJe3-oPAQWpp2GlgLRU8ky3uQ9mlLMEJJK-JEwX61n513SEekeMhm4fToOqgdf9xWPE2JsWTMHhvN5TDllhpOVGOv7BZ38-LPpVrEskEk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1478350757&Signature=iFLNSz1g1X~qxiIfosP7uxXlNHG024Y-mBr2p21lfZHyNK-OrMT6Sj14fWfpEvUs5SpbW9khZikhpGu-cnb8rjWGR9u7kqzltJ473T0Cq1o9HIMgu8ETaaBfJisO-hbGKK4FRce3f2GjPdRHTxMrVV1hi~qKR39CrnIwIGbxssA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_en&type=PROGRAM&Expires=1476426980&Signature=SltaFwqsSRyukH9f9E1Wc~wmPk4DzqjbJfWrGYwCifI3lUrXTfuL5ZD4-5U~uoqRf3WwZ10lqn-8qpNmIR955EpXyEfWJhDXzkQj-lRdgmdLkwFSEXj18~BewxhTj20PXUUKMYd26-wsynuu5UO6~66gWcm9EzytGUjPjHYY4so_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://www.universetourdownload.com/UPbVxfFr8e70JW8CH3BmHlWmrTnY1lySbyGpemDQ0NWI0nd98HVgXuu owfUICsd8QVV7A9jgI61c05cxm_un2jLC6LeACDrESWCtTbFCPBWjBU7e4ztyW0zVKtCMcouQWepTsh0_KreOZi07rPz k94z6an8OJi_nEVDiuQqwbU_hPH1bGXO0p0gdah_CmEQ9G_lfJySPts0n40ZRx2wDEiYOTwFg==-G1MAAGRgnq2tGQn0DdiAA5cSWXQAnWC4AXMunXxj7A3tzufLfBw0kgh vOZ5OYOJJ2j5LvLjKR78qcTw6949aBRt4Y9EYf9dACwiStAkTlAEAQ==

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1476265943&Signature=dfPH~hjmZjQJw-6~~l9yMC-JJI9rNs4uMpiIHkRXy4mXYW8B~CGufPXIipOpSl5px7GDGIlhTVQ22yVlO0Qe~N355q2AqtNJ~rKjq~8RBXm2i7qgJOXaFjfQzqwpDDIGPTuX27SO9aogEmcn1Ex2L5PvVUwYfLVw1Sd~PScgZ6k_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1477217212&Signature=DldAQ8lDL9QrQBcih8YdAuavK8OQbMsaZHzVtMFS~rBfv-fDmderb3rYWfgnsk6ntfXr1YcdMdi6yfBxX2nJJvLrZEcbKb843IcwEqo-g8c1UCMuQL1KrT4Tz2ZmKxeoMa8IFsT8VrYhjBNsY1Shzpmgr-w7LqIv-SkPgSOmc0w_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_en&type=PROGRAM&Expires=1477793894&Signature=Tj2T~BJ-2NW-GR-DnFANpTiSMBhTXeZMOPxT6HmsYbaRJROn9RWffOsWWhMFk~4oxbiLG2T3zanL4hDkxnR9tfXt~j2lLrHu-MfGJJ69IwgMliHSpkxeaW7DvQHIV7I9j50OwW-hD8qx2Yv2T8Ro4pGqyPu2IAcZpqwoin2VCVI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_br&type=PROGRAM&Expires=1471347085&Signature=ZobJajoRmtl-7qAvH1O-OPoLfW8yoAC-XajKerx-nvDkHTdaysWCAUBhp1p6Ou2Om6IUq5ms2RqLXtixW1gcUsI3-H6yW0p-EsehFdeX4cHobyTcjT8RUzXovKDB2AyQvU203Sg~TXo4wjyEphahIpUlDw2Cq-PmEXIYfjpInnM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_en&type=PROGRAM&Expires=1477354093&Signature=J6sitBdht8K7OM5yxG3hlLuFubRwRW5Sg5b3iFGqxPsQjH-LiheW4Wa3zhjmcyGIBxkvwqFORwHpl3XwmpnxAVExOASokVBR7h2VjihEWa83VJ7DxVzXpPHDlQqOJn7XfMRDNJg83Kmc5BWxSBSK~2isx8mmmGpKCZbP4DY-ApM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_en&type=PROGRAM&Expires=1441320801&Signature=Tq1Avkn5r3oAmsmqLYLnkxaWjKPaA-42mJybY0zJ3i6AuynTGVwCBaeWLHpR5qsAK-DC2iho3Q-KRQR9-Kg6S3V69wm0jRxc~aJYvyz4eo5t4gFZcItKt2MvyuGW0I0NlUs6KI6gyHoXzeREHU2tdzU9Dw1RghoINR80Ttoz7nw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_en&type=PROGRAM&Expires=1451633515&Signature=QXj0JJcT0~N37vGGIDtPCUYEWyz6ykZaiZEBye36CSIJOQK57txLy-4Ol9qUKFLOQAquxO0-h-qTtY8sbyvtfT6ExMR5gDi9DaX5GHkbSRMLEeicy4KcfS8hfxRedGwH~DjWwW8LqBHZe1SLyb-YbaScfzN6b-R6P9iAf-Jjfuo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

http://gsf-cf.softonic.com/f1d/fa8/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3336145&instance=softonic_fr&type=PROGRAM&Expires=1472630911&Signature=Dp0JlDomyOPcIxA3R0BqHbAJ4nglA8igM7OeLegiN3J2TZAk5B~K-d-eNQBFyhgkuEt1CHJdLRCEAtTj4ELd0fmZf6eCJX67qN1d35OFhW-1cV2etOj~l~lN2OFucvHBIJuU4oo~vVsGwRUpnUp3ZGmVHH2I0nQUKm3ScJ3r~-8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=SuddenAttackDownloaderV03.exe

Latest 30 of 46 download URLs

Scan suddenattackdownloaderv03.exe - Powered by Reason Core Security