biclient.exe

Better Installer

Somoto Ltd.

Somoto uses a monetization platform known as the 'Better Installer' to provide the ability of 3rd party developers to bundle various adware packages through an affiliate pay-per-install program. The application biclient.exe, “Better Installer Host” by Somoto has been detected as adware by 20 anti-malware scanners. Includes the Somoto BetterInstaller, an adware installer that will bundle offers for additional third party applications, mostly adware toolbars, with legitimate softare and may be installed without adequate user consent.
Publisher:
Somoto Ltd.  (signed and verified)

Product:
Better Installer

Description:
Better Installer Host

Version:
2.0.0.0

MD5:
ac8f7611f353ca9803fad5ff81900678

SHA-1:
de33325e686c82c12db1f95f39e94ac746f5b5b5

SHA-256:
ef72a8db980a2c299006b1c32b6ab0a74fd00dfc131c6ae7f13b392adf4159cc

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Uses the Somoto 'BetterInstaller' to bundle additional (unwanted) software during install without adequate consent.

Analysis date:
5/9/2024 2:33:43 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Somoto
7.1.1

Avira AntiVirus
APPL/Somoto.Gen2
7.11.123.168

avast!
Win32:Somoto-F [PUP]
2014.9-130728

AVG
AdInstaller.Somoto
2014.0.3644

Bkav FE
W32.Clod3e8.Trojan
1.3.0.4613

Boost by Reason
Optional.Somoto.I
188838

Comodo Security
Application.Win32.Somoto.d
17558

Dr.Web
Adware.Downware.1184
9.0.1.0329

ESET NOD32
Win32/Somoto
7.9255

F-Prot
W32/SomotoBetterInstaller.A
v6.4.7.1.166

G Data
Win32.Application.Somoto
14.2.22

Kaspersky
not-a-virus:Downloader.NSIS.Agent
14.0.0.4550

Malwarebytes
PUP.Optional.Somoto.A
v2013.11.25.02

McAfee
Artemis!92C732231B79
5600.7222

NANO AntiVirus
Trojan.Win32.Agent.cruvhh
0.28.0.57029

Panda Antivirus
PUP/MultiToolbar.A
14.02.11.11

Reason Heuristics
PUP.BetterInstaller.Somoto.I
14.8.7.17

Sophos
Somoto BetterInstaller
4.96

Vba32 AntiVirus
Downloader.Agent
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
26350

File size:
223.1 KB (228,432 bytes)

Product version:
2.0.0.0

Copyright:
(c) 2012 Somoto Ltd. All rights reserved.

Original file name:
BetterInstaller.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\biclient.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/19/2011 5:00:00 PM

Valid to:
9/19/2014 4:59:59 PM

Subject:
CN=Somoto Ltd., O=Somoto Ltd., STREET=PO Box 58096, L=Tel Aviv, S=--, PostalCode=61580, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00841D099D16B738F34172FEEFE1D2574F

File PE Metadata
Compilation timestamp:
5/24/2012 2:31:06 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:7xOP3+LdB0XczQDfCli9gm3XD/vVev9GGBFCZ2LipO23zkb5c6VsSIVeWr:IOm1QiLVIjCZ2LipOFe7H

Entry address:
0x17941

Entry point:
E8, E7, 6C, 00, 00, E9, 79, FE, FF, FF, 55, 8B, EC, 83, EC, 04, 89, 7D, FC, 8B, 7D, 08, 8B, 4D, 0C, C1, E9, 07, 66, 0F, EF, C0, EB, 08, 8D, A4, 24, 00, 00, 00, 00, 90, 66, 0F, 7F, 07, 66, 0F, 7F, 47, 10, 66, 0F, 7F, 47, 20, 66, 0F, 7F, 47, 30, 66, 0F, 7F, 47, 40, 66, 0F, 7F, 47, 50, 66, 0F, 7F, 47, 60, 66, 0F, 7F, 47, 70, 8D, BF, 80, 00, 00, 00, 49, 75, D0, 8B, 7D, FC, 8B, E5, 5D, C3, 55, 8B, EC, 83, EC, 10, 89, 7D, FC, 8B, 45, 08, 99, 8B, F8, 33, FA, 2B, FA, 83, E7, 0F, 33, FA, 2B, FA, 85, FF, 75, 3C, 8B...
 
[+]

Entropy:
6.3753

Code size:
135 KB (138,240 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-52-85-167-7.gig50.r.cloudfront.net  (52.85.167.7:80)

TCP (HTTP):
Connects to server-52-85-167-91.gig50.r.cloudfront.net  (52.85.167.91:80)

TCP (HTTP SSL):
Connects to server-52-85-167-96.gig50.r.cloudfront.net  (52.85.167.96:443)

TCP (HTTP):
Connects to server-52-85-167-150.gig50.r.cloudfront.net  (52.85.167.150:80)

TCP (HTTP):
Connects to server-52-85-167-121.gig50.r.cloudfront.net  (52.85.167.121:80)

TCP (HTTP):
Connects to s3-1-w.amazonaws.com  (52.216.225.16:80)

TCP (HTTP):
Connects to server-54-230-191-218.maa3.r.cloudfront.net  (54.230.191.218:80)

TCP (HTTP):
Connects to server-54-192-159-139.sin3.r.cloudfront.net  (54.192.159.139:80)

TCP (HTTP):
Connects to 131.subnet180-250-66.speedy.telkom.net.id  (180.250.66.131:80)

TCP (HTTP):
Connects to server-54-240-162-99.fra6.r.cloudfront.net  (54.240.162.99:80)

TCP (HTTP):
Connects to server-54-230-46-85.fra6.r.cloudfront.net  (54.230.46.85:80)

Remove biclient.exe - Powered by Reason Core Security