CBSI.AppStore.Main.exe

Download App

CBS Interactive

The application CBSI.AppStore.Main.exe, “Download App Store” by CBS Interactive has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the DownloadCom Spot Install installer. This file is typically installed with the program Download App by CBS Interactive which is a potentially unwanted software program. While running, it connects to the Internet address 212.199.202.121.static.012.net.il on port 80 using the HTTP protocol.
Publisher:
CBS Interactive Inc.  (signed by CBS Interactive)

Product:
Download App

Description:
Download App Store

Version:
1.8.0.209

MD5:
2a5da197d7e43498f40eaba563fa75ca

SHA-1:
496322ea1ebf04c7e44f3929e74c801884d9dbe7

SHA-256:
80cb05775c196105d44b55127c653e2ad10063851052c9eb776e017c62e00eda

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2024 5:56:23 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Bundler.PPI.CBSInteractive.Q
14.10.22.5

File size:
2.8 MB (2,960,008 bytes)

Product version:
1.8.0.209

Copyright:
©2014 CBS Interactive Inc. All rights reserved.

Original file name:
CBSI.AppStore.Main.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
DownloadCom Spot Install

Language:
English (United States)

Common path:
C:\Program Files\cbs interactive\download app\cbsi.appstore.main.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/22/2013 2:00:00 AM

Valid to:
8/22/2015 1:59:59 AM

Subject:
CN=CBS Interactive, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=CBS Interactive, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4E4BA2EE1F4C2B3D88BE589DA3471167

File PE Metadata
Compilation timestamp:
10/10/2014 7:39:37 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:bmbl84oCMcnuUTfmwrj86h2YSMXNJ+OjtfEvAMukGtcOd:bmp84DJc6hPJm

Entry address:
0x1F8F6B

Entry point:
E8, FC, 12, 00, 00, E9, 24, FD, FF, FF, CC, FF, 25, EC, 26, 61, 00, FF, 25, E8, 26, 61, 00, 3B, 0D, 44, D8, 67, 00, 75, 02, F3, C3, E9, 76, 13, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, CC, FF, 25, E4, 26, 61, 00, FF, 25, E0, 26, 61, 00, FF, 25, DC, 26, 61, 00, 8B, C1, C7, 00, BC, 42, 63, 00, C2, 04, 00, 8B, FF...
 
[+]

Code size:
2.1 MB (2,165,760 bytes)

The file CBSI.AppStore.Main.exe has been discovered within the following program.

Download App  by CBS Interactive
Publisher's description - “The Download App is a free application from Download.com that helps update the software on your Windows computer. The Download App will scan your computer and notify you when updates are available for the software you have installed.”
www.cnet.com/techtracker
62% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 212.199.202.123.static.012.net.il  (212.199.202.123:80)

TCP (HTTP):
Connects to 212.199.202.121.static.012.net.il  (212.199.202.121:80)

TCP (HTTP SSL):
Connects to yts2.yql.vip.bf1.yahoo.com  (98.137.201.232:443)

TCP (HTTP SSL):
Connects to syndicate1.hattrick.vip.ir2.yahoo.com  (188.125.80.45:443)

TCP (HTTP):
Connects to phx2-dw-cbsi-xw-lb.cnet.com  (216.239.120.246:80)

TCP (HTTP):
Connects to phx1-dw-cbsi-xw-lb.cnet.com  (64.30.224.172:80)

TCP (HTTP SSL):
Connects to l1.ycs.vip.ams.yahoo.com  (66.196.65.111:443)

TCP (HTTP SSL):
Connects to aa.it.vip.bf1.yahoo.com  (63.250.200.72:443)

TCP (HTTP):
Connects to a195-249-27-67.deploy.akamaitechnologies.com  (195.249.27.67:80)

TCP (HTTP):
Connects to a195-249-27-66.deploy.akamaitechnologies.com  (195.249.27.66:80)

TCP (HTTP):
Connects to a195-215-221-48.deploy.akamaitechnologies.com  (195.215.221.48:80)

Remove CBSI.AppStore.Main.exe - Powered by Reason Core Security