color-my-facebook.exe

The application color-my-facebook.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from static.crossrider.com. While running, it connects to the Internet address tlb.hwcdn.net on port 80 using the HTTP protocol.
MD5:
8dce94408d460e7aa48c0dd5a682b006

SHA-1:
babcaa9213fe7428a4ad3c5a89d4985183dbf4ef

SHA-256:
c6b79cd5198b97a79fa771d732d8520d09332f3d0bd534f43521f5fe7773e7fe

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 9:57:55 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.126.44

AVG
Skodna.Generic_c
2015.0.3312

Dr.Web
Trojan.Crossrider1.26410
9.0.1.05190

Emsisoft Anti-Malware
Application.Downloader
11.5.0.6191

ESET NOD32
Win32/InstallCore.AZ potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.W.gen
v6.4.7.1.166

Reason Heuristics
PUP.InstallCore.ENG (M)
16.7.26.3

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141021

File size:
1.1 MB (1,181,648 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\color-my-facebook.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:52:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:UmYZZFmId1OUKNrbJpENZLbepUHXPqEJ8nfA3kPLpcWeCAZIor2:U5XOUKz6LBXPqE3kjpcJn+s

Entry address:
0xD8AD0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 6C, E4, 41, 00, E8, 91, DC, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
877.5 KB (898,560 bytes)

The file color-my-facebook.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to tlb.hwcdn.net  (69.16.175.42:80)

TCP (HTTP):
Connects to ec2-52-30-150-214.eu-west-1.compute.amazonaws.com  (52.30.150.214:80)

Remove color-my-facebook.exe - Powered by Reason Core Security