xvid4psp_5.0.37.8_r132.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
MD5:
0758a8c5de44980f0ba6c4d055c31650

SHA-1:
84c639e14b18a6819403b2fd413b80090294c148

SHA-256:
88634c4c4db0e052b4601b111852fba6cbf0269c4b35cc35ab4c9cb2baf8abfc

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/19/2024 10:43:00 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Packed.Unknown
17912

Norman
Obfuscated.J
11.20140521

Trend Micro
PAK_Generic.001
10.465.21

File size:
42.6 MB (44,682,591 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

File PE Metadata
Compilation timestamp:
6/7/2009 12:41:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:uBz9kYxlg87Lat/ERyPLWClQVeM/PsnnaT+juntHb8Odf8nz0XCG7Rxm:uBz9hxl97uTDWCij/kns+jutHbPs0SG2

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9989

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file xvid4psp_5.0.37.8_r132.exe has been seen being distributed by the following 21 URLs.

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1448935681&Signature=P0tG9mJjGSI5HLtayE2eRehjRPKe5pSkabt3LVICF8vKlrkreD0f2IJc~wYp9lms50ex05azqf1RFU3pwMrv~UoIsHbUdrgQ~Czxl-Y7piAIm1o~eeU4Wsu3pVL2H~dmj1wNmxUKQtwUI~2Bwab2ThC5rAaXJiVg28zVirbjDdc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=XviD4PSP_5.0.37.8_r132.exe

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1476234929&Signature=etXygNHCaS98lWIt7mkvJnIC5glS8yspy-2cByCX9AHFD7gdL5u23SH5xSEpP~48dSFaAN9gS1YZn7C24-i6cMeGNotKXTzGyZn~sm2KbRUJfXx4Z21IrgWWRHqKEwoGadXHb1sY4AZOD22zrVGRkVjDsgC0O89WZV35jLXBtP4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=XviD4PSP_5.0.37.8_r132.exe

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1477634733&Signature=btZZzOZMlpNjuMqVDzY9ygjncctcrI-oaO0B7CfQCiT2sY0JVmTVKdAWOSnIo~dxZyHXMHr9WN1JEaoJtdUEiibslkQUzEAS7yOHXSZeKmrSZwFzw~afoi4LUq2hD6qn54FP5KC9dqqGW1QpPlkSXcVequMw0M01htF4nWDfcVY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=XviD4PSP_5.0.37.8_r132.exe

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1478824611&Signature=L9c67aHMT9o3dnWtbWBe36yV-nM6Gbnds-TUNhLAYyp8aiYjUqCaQi8VFkfm1~J05hhN-Jd-wNyor-qVEpCNudrJSNfXd6cSlWbF9lRnEnz1nL09y42lgZ47bT9fn4QvL0D4-Rs94qW5KcFXgjaQXe9tlvx63Ip5Z9ghOJjCwig_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=XviD4PSP_5.0.37.8_r132.exe

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1475763886&Signature=B7-RUJD5ASp-hP2kOPeDFgTIEsaLuHlKrRt~UQ33v-eHjgJuy-Tlfl9fhCpQrlIWNlf8b31un6v5qHM0DHGOTgxSEybrAjAMcPSHwy6U5Egnm2-khYrdY8UEGRVFvj-SVLPxVKr91muQUqzWsoiB14E~9I1lq4eobDslnOULY3A_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=XviD4PSP_5.0.37.8_r132.exe

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1476918269&Signature=MQzypaCLjEaqNPHIAALdpN9iBAoxlS-Zdo6Z9t06J-pXpMXEzmjhntK4cX3E48Hz480M2tfqtrG8GYNWF9GrNxVJUUS--9i~HbGS~E5x5ZnbdP~solosY35rgQIKl8x12YcN1LfVTPbd9s-4l228rkqCktXQ6l2TT6EL~VDSDtY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=XviD4PSP_5.0.37.8_r132.exe

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1481096921&Signature=DO8Ef1hGjp2z4soVxusuX3-KppSiuwfWN6fzkk98MHNEnUF32vSrIAsi3z1dDIYTtq3wYkL1I1UFyOoBTwpFXVBp98qlsWh1VuiuH2FuntXWIgfML9skJYw7yFBrNZe281-V080gvnMl-xccpphrEoCut6gf4UYajVmwmzB4mrI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=XviD4PSP_5.0.37.8_r132.exe

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1476109038&Signature=RzpWmrjfWuulPXBJQHwiVtbvyNG9QmPtUlU4gkrjuNvRfKRmAoPgiaADgRUk4pqFly8co2DLrGvZyEGmyUj~tmD6Qmv11aA5AB-qbeOXNdg0c6Ufz40IewH4BEnqwvRi4eK7QITwq-EfYklfGKe33ty8cRRlEjPE-HTG0Gk9je0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=XviD4PSP_5.0.37.8_r132.exe

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1477807833&Signature=VvG-iLzI1vTHnE-EDSCbaj1Dd-i7kCKbK1FwY1PHG29oTuWMadbR-lm3GnUcpPB5D~NcPLqi5Jx-o3bpzDce6weN4Ti2OLfI9lh2jXOvY1L4brx9Z5eaKrhnijcOVOXICxhm3DIZKZfFnBbIXS2O-vJKW890FYmhZ4sXd0fSNbU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=XviD4PSP_5.0.37.8_r132.exe

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1424076197&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=LvI0RXslcZiVlDJzq7wp~JY6qlkjaiR1TpOcOTqoKyMr2q5BCunez-EeJjoOk4vPf4UqT~-9UHLo7klNkGtr1tmxTQGmLCTwHb-Y~B1cLGIuTuAWYJKNhhM0n3Y1XPUHnhB6n0vniRGj35CH3q5zN-NpONPMpTHqVvFHUVhN2WE_&filename=XviD4PSP_5.0.37.8_r132.exe

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1474240924&Signature=Vi6BIP7efafeob9BgXtAbx~F2hatJTx1hHHddHooAbs5vdKJfwqdH9b25GEvccJ5CXu8GwgSJyi-ZRfKX1OELSxvmjkrFFeFpwQWY~-6pcMoe4ySzT~oqD8jaPBzVntddhkWGztpwCNtJv~oC4T7OFhzthwDosC5e-yMnQjlveM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=XviD4PSP_5.0.37.8_r132.exe

http://gsf-cf.softonic.com/84c/639/.../file?SD_used=0&channel=WEB&fdh=no&id_file=69530&instance=softonic_en&type=PROGRAM&Expires=1449921113&Signature=hlvrSOuZVcTmxMoy~3eMes1tPsnYniuyMcEASWYMEgZWsYjBD9UGiqSst8t5jz3z2fO3oPORgvxsABtrZWo20l7o7cHPvL4JZIPsnEmt89FeGFwM3-WC19QPtD9X88F4kO056JEGeLH109bh~Q0K3zkrSluxHtPI2uRit~rgjmw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=XviD4PSP_5.0.37.8_r132.exe

Scan xvid4psp_5.0.37.8_r132.exe - Powered by Reason Core Security