baixaki_google-chrome-portable.exe

program

No Zebra Network Ltda.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application baixaki_google-chrome-portable.exe, “program Setup ” by No Zebra Networka has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The installer is marketed through download protals and search ads as Google's Chrome web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
No Zebra Network Ltda.  (signed and verified)

Product:
program

Description:
program Setup

MD5:
7bbbf4db7a0c4a792102a3e9f97c9e75

SHA-1:
ca62fb062127305fa293c6fcc2e058c5e719f20c

SHA-256:
48660881f1f2501ec32716a65c807ec7615b6014417227824f643f6b320ea0de

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 9:25:55 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore (M)
17.3.16.12

File size:
1.8 MB (1,894,832 bytes)

Product version:
3.1

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\baixaki_google-chrome-portable.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
7/21/2016 9:00:00 PM

Valid to:
7/22/2017 8:59:59 PM

Subject:
CN=No Zebra Network Ltda., OU=IT, O=No Zebra Network Ltda., L=Curitiba, S=Parana, C=BR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1FDFF906F277277EE6A4CC1D15123306

File PE Metadata
Compilation timestamp:
5/29/2012 8:51:48 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B8, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 56, EC, FF, FF, E8, FD, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, E8, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file baixaki_google-chrome-portable.exe has been seen being distributed by the following URL.

http://www.towerbitscenter.com/Eb7AbHzboGvqV6crf1cbxpEcyExExYCnSiMNteIdBsqJmPWONKiebhJAGl8jmILqTFOoy5qFkyJM2e_7uPWA7s2qSuc2_IMDOsDCIapcM6jcFsoTZK0jllBJRVunW3c1fkTA1HLKdDc4E5KWLu5wMnHincSMVPmVV8NNrxeb4IfSZWr6twUncNGvul4ICVm254Y1LVNTevqo9tNMqy9lMIHzEhQMvXC0uHIKDUTH52zOnyZRQ3vwuykLiLaDAeW0Z17yX7kTZ32EyhYxxfii 6ckNdS3LuX2WO_dJvkeKN9o8hDKmru7f8fV03DD_1iAXf1DYOiNiKmUsNgqzNRUstPicbR2cBN9I7WtLpRH0UIj8a7VZ8MTmCImse0VYUeKYt5K1wRid2rp7vVB0 2CnOjJ3hWcd2GBY O7R8XEBHs7Ue GTUTS7OZVqCO5HIMXfVLO0HKeDwAp3msz87jolTv mcsTHZakduoB7npZG70idR6GwFONlJ6QgzqL89tLwfxkSKXTUZutdvieIRys8D6hQNEq wp7Kvmk6pWvs_w75gVhxFL5JoAMtHkxzBWsvUW v1vYIUk6Lq8k9K6u x2PphpgeA==-G4sAAGRwXqoLCY6H6kPzeFEnBy7_6XqQRNtyKM0b7BiXgWpX7r73k7iu7TkHbbbT6snJg9Fjg9bPutv3CwVfULVtdtYgc3sXUItIAcLXCAIxpApzSLBsQk24dwbqXyP7jloG

Remove baixaki_google-chrome-portable.exe - Powered by Reason Core Security