2048_game_downloader.exe

TODO:

Start Installer

This is the InstallMetrix bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application 2048_game_downloader.exe, “2048_Game_Downloader” by Start Installer has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the InstallMetrix Software installer. The file has been seen being downloaded from downloadhop.com.
Publisher:
TODO: <Company name>  (signed by Start Installer)

Product:
TODO: <Product name>

Description:
2048_Game_Downloader

Version:
1.0.0.1

MD5:
be3e7c55538e7349887f036a96f181d7

SHA-1:
f21d2bd5775a7123a5d69239c3621a2c267141bb

SHA-256:
a5f8448e1c005fa970bf6095baf06fa3f77aa267680228e29819e77062ae2164

Scanner detections:
9 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
5/8/2024 8:03:11 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-gen [Adw]
140813-1

AVG
Generic
2015.0.3366

IKARUS anti.virus
PUA.InstallMetrix
t3scan.1.7.5.0

Kaspersky
not-a-virus:AdWare.Win32.Agent
15.0.0.463

nProtect
Trojan-Clicker/W32.Agent.1958040
14.08.31.01

Panda Antivirus
Trj/Genetic.gen
14.08.31.02

Reason Heuristics
PUP.StartInstaller.U
14.8.31.22

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Threat.5063683
32210

File size:
1.9 MB (1,958,040 bytes)

Product version:
1.0.0.1

Copyright:
TODO: (c) <Company name>. All rights reserved.

Original file name:
InstallerManager.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallMetrix Software

Language:
English (United States)

Common path:
C:\users\{user}\downloads\2048_game_downloader.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/29/2014 6:00:00 PM

Valid to:
7/30/2015 5:59:59 PM

Subject:
CN=Start Installer, OU=Start Installer, O=Start Installer, STREET="660 4th Street, Suite #427", L=San Francisco, S=California, PostalCode=94107, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
698FCE4EEDDA7C3853C0A7CDE049BA16

File PE Metadata
Compilation timestamp:
8/4/2014 5:23:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:RyuMBg2Xgc9iqYIpfPAH3h8gYpGA8Ly9wES0jlpPe9m+/AWiL3IjYDBRdZj:kfg2X3iqRPAR8gQP8Ly9wES0Qm+/AWS/

Entry address:
0x110CC4

Entry point:
E8, 2F, 7D, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, 40, 7F, 58, 00, 75, 02, F3, C3, E9, B6, 7D, 00, 00, 8B, FF, 51, C7, 01, 90, ED, 55, 00, E8, AE, 7E, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, C8, D8, EF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 83, C1, 09, 51, 83, C0, 09, 50, E8, ED, 7E, 00, 00, F7, D8, 59, 1B, C0, 59, 40, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, 35, A4, 82, 53, 00, 57, FF, 35, 68, AB, BC, 01, FF...
 
[+]

Entropy:
6.2694

Code size:
1.2 MB (1,273,344 bytes)

The file 2048_game_downloader.exe has been seen being distributed by the following URL.

Remove 2048_game_downloader.exe - Powered by Reason Core Security