7zip_rocketfuelinstaller.exe

Verti Technology Group, Inc.

The application 7zip_rocketfuelinstaller.exe by Verti Technology Group has been detected as a potentially unwanted program by 4 anti-malware scanners.
Publisher:
Verti Technology Group, Inc.  (signed and verified)

Version:
1.0.137.0

MD5:
17d4bce84de7732f4af9cd8c3b8ff41d

SHA-1:
cbe3dc4aa8b6c235e0ecfccb35dc86342550b55f

SHA-256:
b1335e4b87454f3600b9f6c1f719d680e16a4051135938d66cfb0c1f89392516

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
3/25/2014 3:40:58 PM UTC  (eight months ago)

Scan engine
Detection
Engine version

avast!
Win32:Adware-BGF [PUP]
2014.9-140325

ESET NOD32
Win32/Verti (variant)
8.9479

Reason Heuristics
PUP.VertiTechnologyGroup.Y
14.3.25.11

VIPRE Antivirus
Rocketfuel Installer
26894

File size:
561 KB (574,448 bytes)

Product version:
1.0.137.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\user\downloads\7zip_rocketfuelinstaller.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/14/2011 5:30:00 AM

Valid to:
11/14/2013 5:29:59 AM

Subject:
CN="Verti Technology Group, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Verti Technology Group, Inc.", L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E5A8F44B995DF01701554FBF18173B7

File PE Metadata
Compilation timestamp:
9/5/2013 7:56:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:qDgMTDNq8Rac0grpCR/fp5gsGP71PzBoL/xsTkKFYrfaC2z7aSkBI6nuZqtmgOVk:ZMTDNBYc0gkR/fp5gsGP71PzBoL/xsT8

Entry address:
0x2EA8F

Entry point:
E8, F1, 9E, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 38, 21, 46, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 3C, 21, 46, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, E6, 10, 00, 00, 85, C0, 75, 06, B8, A0, 22, 46, 00, C3, 83, C0, 08, C3, E8, D3, 10, 00, 00, 85, C0, 75, 06, B8, A4, 22, 46, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Entropy:
6.7280

Code size:
278.5 KB (285,184 bytes)

There are 6 known code variantions that share the same compilation structure.

2 / 68      (PUP)
gg5cm4cr.exe.part  1.0.137.0  (b1048362f9393c07c86acbf7e9bcd805e0cfd474)

2 / 68      (PUP)
xvid_rocketfuelinstaller.exe  1.0.137.0  (718c3278036bfcb86289b494fa6e5a9b0dd4a834)

2 / 68      (PUP)
blinkxbeat_rocketfuelinstaller.exe  1.0.137.0  (dfee2e8cc648eef9d237b86eefb755dc7d7e6e9c)

6 / 68      (PUP)
mixxxdj_rocketfuelinstaller.exe  1.0.137.0  (282aa03e6ad1bff97c689c7c09abc729e48a42a8)

5 / 68      (PUP)
mediaplayerclassic_rocketfuelinstaller.exe  1.0.137.0  (18283f2ab81a6ceb6218229b20fad92b6eb1d831)

2 / 68      (PUP)
tinymediaplayer_rocketfuelinstaller.exe  1.0.137.0  (5d8be228887ac5f4e584611b3f259f8a15490a98)

3 / 68      (PUP)
MediaPlayerClassic_RocketFuelInstaller.exe  (29cfed5052b5170bfea24b0359094d1fbb937689)

3 / 68      (PUP)
Xvid_RocketFuelInstaller.exe  (5cd09a38c1839de456ca9daecb7beff92afb0d30)

4 / 68      (PUP)
TinyMediaPlayer_RocketFuelInstaller.exe  (1171f22492186f95f219cd56cf2e16f176f2e2f7)

3 / 68      (PUP)
MixxxDJ_RocketFuelInstaller.exe  (891e8e6cc9f191862e6dcdafc58b933eec0690b0)

3 / 68      (PUP)
RealPlayer_RocketFuelInstaller.exe  (4527edb45464905fc1005a384a462fcd7e26f5dd)

2 / 68      (PUP)
140231204_setup.exe  (733cb67c497f12bd30617ea105b17fe1316e22a1)

15 / 68    (PUP)
31283.exe  (a801f169b3117503b50b3f380724dfcf957ee99a)

23 / 68    (PUP)
520425.exe  (ecad31ab737499b60c7c2db98bcfab49fb908e8a)

5 / 68      (PUP)
13154013.exe  (4731704b8717918dea80ad6d410af3b9ab6021d8)

1 / 68      (inconclusive)
pagealicious_rocketfuelinstaller.exe  (c6ee4ba12831d581f66660c28047e7409b092d6d)

15 / 68    (PUP)
audacity_rocketfuelinstaller.exe  (299b689752ea63c6ed5f28b781ca74eca8934035)

6 / 68      (PUP)
divx_rocketfuelinstaller.exe  (877e98a7f55ee3499e94a79c59a23ac1b06e71c5)

10 / 68    (PUP)
2301223.exe  (4c12d9a55b8fcf1a98c8ccf15155e934c8eb9ee0)

13 / 68    (PUP)
flv2pc_rocketfuelinstaller.exe  (da73d23f7c298f8ef49c8220ed06b56ff2b9639b)

10 / 68    (PUP)
fixcleanrepair_rocketfuelinstaller.exe  (10064ddd9454694d8e943423e0cf56b18e455365)

7 / 68      (PUP)
qbittorrent_rocketfuelinstaller.exe  (0920335a50d1992c640d50c28f139c12b17f32cc)

Detection Incidence by Country