bitbox browser in the box chrome edition - chip-installer.exe

CHIP Digital GmbH

The application bitbox browser in the box chrome edition - chip-installer.exe, “CHIP Secured Installer” by CHIP Digital GmbH has been detected as a potentially unwanted program by 39 anti-malware scanners. The program is a setup application that uses the Covus installer. With this installer, users are expecting to download Google's Chrome web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
CHIP Digital GmbH  (signed and verified)

Description:
CHIP Secured Installer

Version:
1.0.0.0

MD5:
d560d5d066c7e9c601b22953cd6a6035

SHA-1:
3b69ee5f2c308fe527bf3f613a13f77173f4d07a

SHA-256:
1479cdea3ef3fdc689034a125dd515226aeaf1abc83b0814b30f911ae0cdd64c

Scanner detections:
39 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 10:26:22 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1602076
867

avast!
Win32:Adware-BLN [Adw]
2014.9-140920

Baidu Antivirus
Adware.Win32.Illyx
4.0.3.14920

Bitdefender
Trojan.GenericKD.1602076
1.0.20.1315

Comodo Security
ApplicUnwnt
18107

Dr.Web
BackDoor.Cybergate.1
9.0.1.0263

Emsisoft Anti-Malware
Trojan.GenericKD.1602076
8.14.09.20.07

ESET NOD32
Win32/GameTool.BB
8.9603

Fortinet FortiGate
W32/FrauDrop.ADJIS!tr
9/20/2014

F-Secure
Trojan.GenericKD.1602076
11.2014-20-09_7

G Data
Trojan.GenericKD.1602076
14.9.24

IKARUS anti.virus
Trojan-Dropper.Win32.FrauDrop
t3scan.2.2.29

K7 AntiVirus
Riskware
13.176.11584

Kaspersky
Trojan-Dropper.Win32.FrauDrop
14.0.0.3221

Malwarebytes
Trojan.Inject.RRE
v2014.09.20.07

McAfee
Artemis!37BD65F12E99
5600.7001

MicroWorld eScan
Trojan.GenericKD.1602076
15.0.0.789

Norman
Suspicious_Gen4.FXLPV
11.20140920

nProtect
Trojan.GenericKD.1602076
14.03.27.01

Qihoo 360 Security
Win32/Trojan.Dropper.0c3
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.20.19

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R00UH07C914
7.2.263

Vba32 AntiVirus
TrojanPSW.Ruftar
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
27776

File size:
1.1 MB (1,101,648 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014 Chip Digital GmbH

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus

Language:
German (Germany)

Common path:
C:\users\{user}\downloads\bitbox browser in the box chrome edition - chip-installer.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/25/2014 1:00:00 AM

Valid to:
2/26/2015 12:59:59 AM

Subject:
CN=CHIP Digital GmbH, O=CHIP Digital GmbH, L=Muenchen, S=Bayern, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0D160B8252A4F0A16FE1255FA0A22E2B

File PE Metadata
Compilation timestamp:
8/18/2014 3:33:31 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:Fq5TfcdHj4fmbQ2qZMUm0G8eiLsxkG5NeQU6:FUTsamUxZrG87GDn

Entry address:
0x18D870

Entry point:
60, BE, 00, A0, 53, 00, 8D, BE, 00, 70, EC, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
336 KB (344,064 bytes)