13070760407177157547.exe

Installer

Program Installer software

The application 13070760407177157547.exe, “Installer Setup ” has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from installer.jdownloader.org and multiple other hosts.
Publisher:
Program Installer software

Product:
Installer

Description:
Installer Setup

MD5:
144994b755d5e406f7e823a400342949

SHA-1:
1380ee3c22937ce59ac48907f88f6236d0e1be4d

SHA-256:
69c57b3b00d68eb45e552b96d69d00036734291bf6055dfe029d94640ff66879

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/18/2024 1:11:33 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/InstallCore.A.2387
7.11.217.66

Reason Heuristics
(M)
16.5.11.0

File size:
722 KB (739,280 bytes)

Product version:
5.1.8

Copyright:
Application

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\13070760407177157547.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:makEa8gmV4BbASfihlu9XP/MTnu51HyA0G03UWsmS1imzaDtBwRjIq4hbr:mJE1gmiNAsiTuF33HyAp8S1iHBwRqh3

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8556

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file 13070760407177157547.exe has been seen being distributed by the following 6 URLs.

http://installer.jdownloader.org/rand_13074957530091265532/2434/34/windows/64/_AVGInternetSecurity2015_/.../jdownloader1

http://installer.jdownloader.org/rand_13075251329266351297/2434/34/windows/32/__/.../jdownloader1

http://installer.jdownloader.org/rand_13074292491262784577/2434/33/windows/64/__/.../jdownloader1

http://installer.jdownloader.org/rand_13070996794929937057/2434/34/windows/64/__/.../jdownloader1

Remove 13070760407177157547.exe - Powered by Reason Core Security