7zip_rocketfuelinstaller.exe

Verti Technology Group, Inc.

This is the Verti bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application 7zip_rocketfuelinstaller.exe by Verti Technology Group has been detected as adware by 5 anti-malware scanners. The program is a setup application that uses the Verti Setup installer. The file has been seen being downloaded from inst.get-soft.com and multiple other hosts.
Publisher:
Verti Technology Group, Inc.  (signed and verified)

Version:
1.0.0.1

MD5:
87c5d062a98c3282393d2498fb365d66

SHA-1:
4dd7ebbe1cf165f0feca6a0026324fd7df94f8ee

Scanner detections:
5 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/4/2024 10:16:23 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-BGF [PUP]
2014.9-140804

AVG
Generic
2015.0.3393

Reason Heuristics
PUP.VertiTechnologyGroup.Y
14.8.4.2

Trend Micro House Call
Suspicious_GEN.F47V0802
7.2.216

File size:
354.2 KB (362,664 bytes)

Product version:
1.0.0.1

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Verti Setup (using Nullsoft Install System)

Language:
Language Neutral

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/14/2013 5:30:00 AM

Valid to:
12/15/2015 5:29:59 AM

Subject:
CN="Verti Technology Group, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Verti Technology Group, Inc.", L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2F53536EA4011E81FBFFD28C4B0BEB6F

File PE Metadata
Compilation timestamp:
12/6/2009 4:22:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:7SVBa71UN5us71isS0TlpLHAQ6VQAHGajnNdQyLdbpLGyAfkPjxiAl6zV8p4:ZwlUsS0TDLgzQHGPQ8T/AqjxAzV8u

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 6F, 44, 00, E8, 09, 2C, 00, 00, A3, A4, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 2E, 44, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.8100

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 7zip_rocketfuelinstaller.exe has been seen being distributed by the following 36 URLs.

http://inst.get-soft.com/dl/27/14518/5857/.../

http://inst.get-soft.com/dl/27/14518/51/.../

http://inst.get-soft.com/dl/27/14525/27/.../

http://inst.get-soft.com/dl/27/14518/5857/.../

http://inst.get-soft.com/dl/27/14518/5857/.../

http://inst.get-soft.com/dl/27/17586/27/.../

http://inst.get-soft.com/dl/27/14518/5857/.../

Latest 30 of 36 download URLs

Remove 7zip_rocketfuelinstaller.exe - Powered by Reason Core Security