bluestacks-splitinstaller_native_downloader-8qp2swl3.exe

Somoto Israel

This is the Somoto BetterInstaller, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application bluestacks-splitinstaller_native_downloader-8qp2swl3.exe by Somoto Israel has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the Somoto BetterInstaller installer. The file has been seen being downloaded from getfreezip.com and multiple other hosts.
Publisher:
Somoto Israel  (signed and verified)

MD5:
86d0bbdc1eedf74b0a245df9c6097e22

SHA-1:
c488de0f536a5c45589ffede22dab88822c4c2c6

SHA-256:
569b5d54bd4840edef3fd164ff36ea0d5eb894e66c705e45b9a0def5335e462a

Scanner detections:
13 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 6:45:50 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod9ce.Trojan
1.3.0.4613

Clam AntiVirus
Trojan.Agent-267630
0.98/18155

Dr.Web
Trojan.MulDrop4.11744
9.0.1.018

ESET NOD32
Win32/Somoto
8.9241

F-Prot
W32/Sefnit.C
v6.4.7.1.166

K7 AntiVirus
Trojan
13.174.10689

McAfee
Artemis!86D0BBDC1EED
5600.7247

Norman
Agent.AZBLL
11.20140118

nProtect
Adware/W32.Agent.239064
14.01.01.01

Reason Heuristics
PUP.SomotoIsrael.u
14.8.7.17

SUPERAntiSpyware
Trojan.Agent/Gen-Muldrop
10839

Trend Micro House Call
TROJ_GEN.F47V1016
7.2.18

VIPRE Antivirus
Trojan.Win32.Generic
25014

File size:
233.5 KB (239,064 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Somoto BetterInstaller

Common path:
C:\users\{user}\downloads\bluestacks-splitinstaller_native_downloader-8qp2swl3.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/8/2013 8:00:00 AM

Valid to:
7/9/2018 7:59:59 AM

Subject:
CN=Somoto Israel, O=Somoto Israel, STREET=Habarzel 32, L=Tel Aviv, S=--, PostalCode=69700, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
74F2E607D2905C0E3EA9C8AB59942D25

File PE Metadata
Compilation timestamp:
12/17/2010 5:14:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
6144:PJ380ocGMY0ZqqfQ0TlWqXaxbS/Dv7HyzGhzMKgAPT:PF80ocG7Q4WlWcKbS/Dv7S66Kb

Entry address:
0x380C

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 87, 4D, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, 2A, 4A, 00, 00, 6A, 00, E8, 9B, 4D, 00, 00, 6A, 08, A3, 28, F9, 42, 00, E8, B1, 28, 00, 00, 6A, 00, 68, 60, 01, 00, 00, A3, D8, F9, 42, 00, 8D, 85, 90, FE, FF, FF, 50, 6A, 00, 68, 4C, A2, 40, 00, E8, E0, 4C, 00, 00, 83, EC, 0C, 68, 4D, A2, 40, 00, 68, 08, FA, 42, 00, E8, EF, 2A, 00, 00, 83, C4, 18, E8, E6, 49, 00, 00, 52, 52, 50, 68, 00, 80, 43, 00, E8, DA, 2A, 00, 00, 57, 6A, 00, E8, 29, 49, 00, 00, 83...
 
[+]

Entropy:
7.7638  (probably packed)

Code size:
30 KB (30,720 bytes)

The file bluestacks-splitinstaller_native_downloader-8qp2swl3.exe has been seen being distributed by the following 7 URLs.