dnldstr_aggregator_downloader_v4.0.3.7067_demo_bannerad_winrar.exe

The application dnldstr_aggregator_downloader_v4.0.3.7067_demo_bannerad_winrar.exe has been detected as a potentially unwanted program by 23 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from dnld.ironcust.com.
MD5:
270fc6bfd7f7c34e9f9193d03910c68d

SHA-1:
0fc4c04308529a9ebc81db22bc5b9104967e3428

SHA-256:
1778bb9f4ce51cd86bec1a9481619dccf8e3805fd5c49ba9ae0e4a943bf06210

Scanner detections:
23 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/24/2024 6:39:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur2.GZ.MmHfbW6bfNfi
780

Agnitum Outpost
Trojan.Kryptik
7.1.1

Avira AntiVirus
7.11.177.26

avast!
Win32:Installer-I [PUP]
140908-2

AVG
Generic
2015.0.3351

Bitdefender
Gen:Trojan.Heur2.GZ.MmHfbW6bfNfi
1.0.20.1755

Dr.Web
Adware.InstallCore.239
9.0.1.0351

Emsisoft Anti-Malware
Gen:Trojan.Heur2.GZ.MmHfbW6bfNfi
8.14.12.17.10

ESET NOD32
Win32/InstallCore.BZ potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.G4.gen
v6.4.7.1.166

F-Secure
Gen:Trojan.Heur2.GZ.MmHfbW6bfNfi
11.2014-17-12_4

G Data
Gen:Trojan.Heur2.GZ.MmHfbW6bfNfi
14.12.24

IKARUS anti.virus
Trojan.Win32.Spy
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.183.13358

MicroWorld eScan
Gen:Trojan.Heur2.GZ.MmHfbW6bfNfi
15.0.0.1053

NANO AntiVirus
Riskware.Win32.InstallCore.cysdtp
0.28.2.62483

Panda Antivirus
PUP/MultiToolbar.A
14.09.15.07

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.17.10

SUPERAntiSpyware
Trojan.Agent/Gen-Kryptik
10172

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
Threat.4786018
32938

File size:
604.2 KB (618,712 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\dnldstr_aggregator_downloader_v4.0.3.7067_demo_bannerad_winrar.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:0rFki4cYBl3P7yn0N+R2c8PN1MeQumgxXT5s2ZAZIFBJHzoY:aFp4culf2kyoN1MeQummDS2GQBlr

Entry address:
0x1303D0

Entry point:
60, BE, 00, 20, 4A, 00, 8D, BE, 00, F0, F5, FF, C7, 87, 10, 47, 0E, 00, 0C, E0, 5D, 21, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8400

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
572 KB (585,728 bytes)

The file dnldstr_aggregator_downloader_v4.0.3.7067_demo_bannerad_winrar.exe has been seen being distributed by the following URL.