vdownloader 3.0 português.exe

Softonic International

The application vdownloader 3.0 português.exe by Softonic International has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It runs as a scheduled task under the Windows Task Scheduler. The file has been seen being downloaded from getvdownloader.com. While running, it connects to the Internet address www.sft-pre.com on port 443.
Publisher:
Softonic International  (signed and verified)

MD5:
2ead428200707025774678b8050753f0

SHA-1:
f5408456c1486522184c891ecdecd937b0060a36

SHA-256:
4a907d74bcf4e0c71250076240a59ecceaf07290d63bcff26f858ea2c8bf16de

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 10:02:36 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softonic (M)
16.3.24.22

File size:
286.3 KB (293,152 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\vdownloader 3.0 português\vdownloader 3.0 português.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/6/2009 9:00:00 PM

Valid to:
9/7/2011 8:59:59 PM

Subject:
CN=Softonic International, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Softonic International, L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
707E68E6802EEDABC3757C9005AC1028

File PE Metadata
Compilation timestamp:
8/31/2010 1:09:56 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:M4JZJe7gn5qhG9yn08h1nkTDlKsWaMEObAuKtfLXBJYphoSaR4:M4oU5Ohn1cHRWXA1tfkroSaR4

Entry address:
0x4BE6F0

Entry point:
60, BE, 00, D0, 87, 00, 8D, BE, 00, 40, B8, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 0F, C2, 4B, 00, 57, 83, C3, 04, 53, 68, E4, 16, 04, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
268 KB (274,432 bytes)

Scheduled Task
Task name:
{52E787DC-0B4C-4948-8230-5CFE1E0DFC9B}

Trigger:
Registration (Runs on registration)


The file vdownloader 3.0 português.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to www.sft-pre.com  (46.28.209.62:443)

Remove vdownloader 3.0 português.exe - Powered by Reason Core Security