down_installer_age_of_empires_ii_danish.exe

7-Zip

Free Software LLC

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application down_installer_age_of_empires_ii_danish.exe by Free Software has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from age-of-empires-ii.ine-hn.org.
Publisher:
Igor Pavlov  (signed by Free Software LLC)

Product:
7-Zip

Description:
7z 安装自释放

Version:
9.20

MD5:
bb662b9a26dafa9d0e489b7c7a5ba3d0

SHA-1:
67ff5db9e402aba13b92fa67dd060afafb2ed0e3

SHA-256:
8bed06cde12bdf135a3f24107598b1e1ece98439cbda90544b17afc962e02124

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/3/2024 7:14:17 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/InstallCore.Gen9
8.3.1.6

avast!
Trojan-gen
150602-1

AVG
Generic
2016.0.3089

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Vittalia.71
9.0.1.05190

ESET NOD32
Win32/InstallCore.QW potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.AG.gen
v6.4.7.1.166

G Data
Win32.Application.InstallCore.CM
15.6.25

K7 AntiVirus
Unwanted-Program
13.204.16128

Malwarebytes
PUP.Optional.Vittalia
v2015.06.03.03

NANO AntiVirus
Riskware.Win32.InstallCore.dgjqfu
0.30.24.1636

Reason Heuristics
PUP.Installer.FreeSoftware
15.6.3.11

Sophos
PUA 'Install Core Click run software'
5.15

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
3.12.26.4

VIPRE Antivirus
Threat.4782551
40786

File size:
872.9 KB (893,832 bytes)

Product version:
9.20

Copyright:
版权所有 © 1999-2010 Igor Pavlov

Original file name:
7zS.sfx.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Language:
Kinesisk (forenklet, PRC)

Common path:
C:\users\{user}\downloads\down_installer_age_of_empires_ii_danish.exe

Digital Signature
Authority:
Starfield Technologies, Inc.

Valid from:
8/1/2014 12:08:01 PM

Valid to:
7/22/2015 1:23:49 PM

Subject:
CN=Free Software LLC, O=Free Software LLC, L=Wilmington, S=Delaware, C=US

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
27DD6AADCC34E6

File PE Metadata
Compilation timestamp:
11/18/2010 5:27:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:WddFMz0E5aF0JYsogmB7/aYZ+OWxI7brCXIB/svGfM2LLwMyt:Wdd6z0Oods2B7yrtUO8/s+fLAft

Entry address:
0x1373C

Entry point:
55, 8B, EC, 6A, FF, 68, 28, 69, 41, 00, 68, 36, 37, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, EC, 60, 41, 00, 59, 83, 0D, 24, C9, 41, 00, FF, 83, 0D, 28, C9, 41, 00, FF, FF, 15, F0, 60, 41, 00, 8B, 0D, 14, A9, 41, 00, 89, 08, FF, 15, F4, 60, 41, 00, 8B, 0D, 10, A9, 41, 00, 89, 08, A1, F8, 60, 41, 00, 8B, 00, A3, 20, C9, 41, 00, E8, E0, 5E, FF, FF, 39, 1D, 00, A7, 41, 00, 75, 0C, 68, C4, 38, 41, 00, FF, 15, FC, 60...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
81 KB (82,944 bytes)

The file down_installer_age_of_empires_ii_danish.exe has been seen being distributed by the following URL.

Remove down_installer_age_of_empires_ii_danish.exe - Powered by Reason Core Security