Enter the MD5, SHA1 or SHA256 hash to search for:        

Summary

Sections


MD5:192d10f7e324719253b210bd790e3df2
SHA1:7cb6881823137fec72aab1558c91254f29df0cd1
SHA256:5ca08316aaa30a147999251a14af68ef6564cd4de3a83d6872a32628aadfce2c
Date Submitted:6/25/2012 3:17:52 AM
Malicious:True
Executable:True
Minotaur Sample ID
164195

FileType Statistics

FileType:
 39.5% (.EXE) UPX compressed Win32 Executable (30569/9/7)
 34.3% (.EXE) Win32 EXE Yodas Crypter (26569/9/4)
 11.0% (.EXE) Win32 Executable Generic (8527/13/3)
  9.8% (.DLL) Win32 Dynamic Link Library (generic) (7583/30/2)
  2.5% (.EXE) Generic Win/DOS Executable (2002/3)


Identity Statistics

Vendors Declaring Malicious:
TotalVendors:
VirusTotal Report:
http://www.virustotal.com/file/5ca08316aaa30a147999251a14af68ef6564cd4de3a83d6872a32628aadfce2c/analysis/

Malware Family Detections:Adware.Downware.325
a variant of Win32/SoftonicDownloader.D

Static Analysis Data

CRC Data
ClaimedActual
0373204


Claimed Compile Date:
Wed Jun 13 10:40:32 2012 UTC

CountLanguage Reference Counts
9LANG_SPANISH SUBLANG_SPANISH_MODERN
1LANG_ENGLISH SUBLANG_ENGLISH_US
Static Analysis Alerts:
  • Packer Detected: UPX
  • URL Detected: http://winrar.sd.softonic.it/universaldownloader-prefetch[ENDVALUE][KEY]NOINT_TITLE[VALUE]Nessuna connessione Internet rilevata[ENDVALUE][KEY]NOINT_MSG[VALUE]

Screenshots


Click here to start video playback

Origin Statistics

URL IDDate AddedURLIPSource
1665976/25/2012 3:17:52 AMhttp://universal-downloader.softonic.it/12000/12536/ud_400/SoftonicDownloader_per_winrar.exeuniversal-downloader.softonic.it.s3.amazonaws.com.Clean-MX

Primary Domain Information

Level 3 (control)205.251.242.149Control
Google207.171.185.201ALLOWED
OpenDNS72.21.203.149ALLOWED
Norton72.21.194.16ALLOWED
Comodo207.171.163.206ALLOWED

Network Traffic Analysis



HTTP Request Data

HostPortHTTP URIMethod
en.softonic.com80/error404?event_short_name=post-download-page&event_type=page_view¤cy=USDGET
screenshot.it.sftcdn.net80/it/scrn/12000/12536/winrar-09-100x100.pngGET
static.sd.softonic.it80/it/css/generated/7143-18234.cssGET
static.sd.softonic.it80/it/js/generated/28068-56497.jsGET
static.sd.softonic.it80/shared/img/universaldownloader/truste_seal.pngGET
v3it.sftcdn.net80/shared/img/icons/icons_sprite.pngGET
v3it.sftcdn.net80/shared/img/universaldownloader/v1_images.pngGET
v4it.sftcdn.net80/shared/img/universaldownloader/loading.gifGET
winrar.sd.softonic.it80/partners-event?event_short_name=post-download-page&event_type=page_view¤cy=USDGET
winrar.sd.softonic.it80/universaldownloader/no-campaignGET
winrar.sd.softonic.it80/universaldownloader-prefetchGET
winrar.sd.softonic.it80/universaldownloader-trackPOST
www.google-analytics.com80/__utm.gif?utmwv=5.2.8&utms=1&utmn=445502843&utmhn=winrar.sd.softonic.it&utmcs=utf-8&utmsr=800x600&utmvp=650x450&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=10.3%20r181&utmdt=installation%20assistant&utmhid=330080728&utmr=http%3A%2F%2Fflashcookie_error_flashcookie_error&utmp=%2Finit_startup&utmac=UA-20034682-2&utmcc=__utma%3D61559850.506382472.1340611253.1340611253.1340611253.1%3B%2B__utmz%3D61559850.1340611253.1.1.utmcsr%3Dflashcookie_error_flashcookie_error%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3D%2F%3B&utmu=qACAAAAAC~GET
www.google-analytics.com80/__utm.gif?utmwv=5.2.8&utms=2&utmn=25354390&utmhn=winrar.sd.softonic.it&utmcs=utf-8&utmsr=800x600&utmvp=650x450&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=10.3%20r181&utmdt=installation%20assistant&utmhid=330080728&utmr=http%3A%2F%2Fflashcookie_error_flashcookie_error&utmp=%2Fstart_api&utmac=UA-20034682-2&utmcc=__utma%3D61559850.506382472.1340611253.1340611253.1340611253.1%3B%2B__utmz%3D61559850.1340611253.1.1.utmcsr%3Dflashcookie_error_flashcookie_error%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3D%2F%3B&utmu=qACAAAAAC~GET

DNS Request Data


DNS Requests
Query
en.softonic.com
screenshot.it.sftcdn.net
static.sd.softonic.it
static.www.softonic.it
v3it.sftcdn.net
v4it.sftcdn.net
winrar.sd.softonic.it
www.google-analytics.com

DNS Responses
QueryResponse
en.softonic.com46.28.209.13
screenshot.it.sftcdn.net46.28.209.54
static.sd.softonic.it46.28.209.70
static.www.softonic.it
v3it.sftcdn.net46.28.209.43
v4it.sftcdn.net46.28.209.43
winrar.sd.softonic.it46.28.209.70
www.google-analytics.com74.125.228.14,74.125.228.0,74.125.228.1,74.125.228.2,74.125.228.3,74.125.228.4,74.125.228.5,74.125.228.6,74.125.228.7,74.125.228.8,74.125.228.9

Discussion

blog comments powered by Disqus