codecperformersetup_vbc1465.exe

White Tech Software LLC

This is the Performersoft setup installer. The application codecperformersetup_vbc1465.exe by White Tech Software has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the InstallBrain installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The file has been seen being downloaded from www.humipapp.com and multiple other hosts.
Publisher:
White Tech Software LLC  (signed and verified)

MD5:
4a16d417c4d756b71edddc8e601637fd

SHA-1:
16e2855c486256527c995e1880dea23ea3b741ff

SHA-256:
d0d86e6d68c369553b87667e756cb58ffa5a75f3f7c47022afbe1445829bacf4

Scanner detections:
17 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 2:34:01 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Downloader
2014.01.05

avast!
Win32:Dropper-gen [Drp]
2014.9-140105

Dr.Web
Trojan.DownLoader9.5231
9.0.1.0361

ESET NOD32
Win32/TinyExeGun (variant)
7.9250

IKARUS anti.virus
Virus.Win32.Dropper
t3scan.2.2.29

K7 AntiVirus
Unwanted-Program
13.176.11684

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.4558

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.01.11.07

McAfee
Artemis!4A16D417C4D7
5600.7269

NANO AntiVirus
Trojan.Win32.MLW.cufiqf
0.28.0.58873

Norman
DLoader.ATLZP
11.20140111

Reason Heuristics
PUP.Installer.WhiteTechSoftware.BB
14.8.8.0

Sophos
Generic PUA BG
4.96

Total Defense
Win32/Tnega.PTFMNQB
37.0.10498

Trend Micro House Call
TROJ_GEN.F47V1220
7.2.361

VIPRE Antivirus
Adware.Win32.InstallBrain.a
25082

File size:
181.2 KB (185,568 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallBrain

Common path:
C:\users\{user}\downloads\codecperformersetup_vbc1465.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/19/2013 2:45:24 AM

Valid to:
12/19/2016 2:45:24 AM

Subject:
CN=White Tech Software LLC, O=White Tech Software LLC, L=Beaverton, S=Oregon, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B6B265A389BA9

File PE Metadata
Compilation timestamp:
12/14/2013 10:17:26 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:Vs7HXJ2Jmv0NFFuUmiwJJlJldp5DWTBfSJnx0UmSS1Ge71wfSXy/oKKnRFP:VsXJ2m4FFuEwJtldHWTBKhx0PSQT71o8

Entry address:
0x88C2

Entry point:
E8, 18, 65, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81, F9, 80, 00, 00, 00, 72, 1C, 83, 3D, 80, ED, 41, 00, 00, 74, 13, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 05, E9, 66, 65, 00, 00, F7, C7, 03, 00, 00, 00, 75, 14, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 29, F3, A5, FF, 24, 95, 40, 8A, 40, 00, 8B, C7, BA, 03, 00, 00, 00, 83, E9, 04, 72, 0C, 83, E0, 03, 03, C8, FF...
 
[+]

Entropy:
7.2298

Code size:
82.5 KB (84,480 bytes)

The file codecperformersetup_vbc1465.exe has been seen being distributed by the following 33 URLs.

http://www.humipapp.com/tiny/.../$uOkAXJA3I145shIp?lang=en&cid=4280

http://www.humipapp.com/tiny/.../$ueANa5A3I0IxkzAV?g=2&cid=4275&SourceId=366&CreativeId=4470607&SectionId=540491&tid=000109b45e6bab9c24cf0b0eba612088e281e

http://www.humipapp.com/tiny/wts/.../4ZVZA3ZUM5mCIU?cid=4154&clickid=0042072966530256996&dfpid=104102740

http://www.humipapp.com/tiny/.../$hd0lZpA3ZUMjvC05?cid=4159&clickid=0024092746520453907&dfpid=101102475

http://www.humipapp.com/tiny/.../$ls0vfpA3ZV40thEX?v=19&cid=4197&tid=DHrd3URblOKhePqeqXEXXPOSW-kuV6Ql4k4CGBt4UjU45r16jdtiZFTpo3UxIhzdMt165D1KBiiIQ776TU3Ug1cuqDwK4-8LMdKNrc40r_p1dxC3PnkEolcp3-_dWKnGBRgdkOj_UsFO9DOZ6q0PPK-4sz6RD4mpo-BzG-_Jmz1VnHpWayudm0kiAq_QGZliXjLH8nhDd-zy58_DshpwW6EeAM4Lk21Q7uOXiUCnZtuU8EFPI4iiwV65qvrMeDdxzXQwq-mGAykfCYb_iBzc5dvkkU2rLzSexchsCmVxBiEZGp-MPgnHvoBynoqlNHAZAGyxnbxA11_ji-Br4hOeUxfKiUkHW8ux9E02FK1BrjVbr7Fn4R0ExxUjLKV_2shsi2sRVZo

http://www.humipapp.com/tiny/.../$jeMUfJlscAcpkg8K?lang=en&cid=3867&gclid=CM6Z9sSYzLsCFbMbtAodBnIAJg

http://www.humipapp.com/tiny/.../$qv8LXpA3I0IxgSQb?g=2&cid=4275&SourceId=366&CreativeId=7191933&SectionId=374999&tid=000100995ba8354aa4eb5afbec32d07942721

http://www.humipapp.com/tiny/.../$nPg4YpA3IwZhuhYX?cid=4200&tid=EI_g1049999l516482s1357p150046t281854m1744647c7779319_688e60-4185d7c7-62934c3-3f11c4b8-1e793a04_nym1CNCo9deZ4KzdNxACGNPjxenz1L_nZCIMOTguMTkuNTYuMjIyKAE.

http://www.humipapp.com/tiny/.../$q UeQpA3I0IxmDAI?g=1&cid=4275&SourceId=366&CreativeId=7191966&SectionId=325761&tid=0000411983a491d754b02bc7ae601c04e853a

Latest 30 of 33 download URLs

Remove codecperformersetup_vbc1465.exe - Powered by Reason Core Security