downloadapp_1_8_0_209r_setup.exe

Download App

CBS Interactive

The application downloadapp_1_8_0_209r_setup.exe, “Download App Installer” by CBS Interactive has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the DownloadCom Spot Install installer. The file has been seen being downloaded from files.downloadnow.com and multiple other hosts. While running, it connects to the Internet address phx1-dw-cbsi-xw-lb.cnet.com on port 80 using the HTTP protocol.
Publisher:
CBS Interactive  (signed and verified)

Product:
Download App

Description:
Download App Installer

Version:
1.8.0.209

MD5:
ea57cf9cc27210b2c35b4f9bd406c851

SHA-1:
e31c00107a5875306535ed170b96ddcb3839d09f

SHA-256:
7453b455818383f0680eaf496346a9ba3636e7c87568c159f7f8e8903c32136b

Scanner detections:
2 / 68

Status:
Potentially unwanted

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/27/2024 2:48:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Bundler.PPI.CBSInteractive.CC
14.11.26.20

Trend Micro House Call
TROJ_GE.D0B8CF11
7.2.330

File size:
29.8 MB (31,276,600 bytes)

Product version:
1.8.0.209

Copyright:
Copyright (C) 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
DownloadCom Spot Install (using Nullsoft Install System)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/21/2013 5:00:00 PM

Valid to:
8/21/2015 4:59:59 PM

Subject:
CN=CBS Interactive, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=CBS Interactive, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4E4BA2EE1F4C2B3D88BE589DA3471167

File PE Metadata
Compilation timestamp:
6/6/2009 2:41:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:bSjJ9rBzG15Qy9tstIAP+nQ8p/pK1tx3dK9R:arY4+QW/E

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file downloadapp_1_8_0_209r_setup.exe has been seen being distributed by the following 4 URLs.

&onid=18513&oid=3012-18513_4-75864009&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=utilities/op-systems-updates&topicbrcrm=&pid=13851806&mfgid=6230860&merid=6230860&ctype=dm&cval=SPIGOTWIN&ftag=DAPc1fe215&devicetype=desktop&pguid=463b73e71a3e4eb6ba130506&viewguid=Tw3Ky7MKxOtWzgXa5MI5mqi3BsSOiTz3Hv0C&destUrl=http://software-files-a.cnet.com/s/software/13/85/18/.../DownloadApp_1_8_0_209r_Setup.exe

&onid=18513&oid=3012-18513_4-75864009&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=utilities/op-systems-updates&topicbrcrm=&pid=13851806&mfgid=6230860&merid=6230860&ctype=dm&cval=SPIGOTWIN&ftag=DAPc1fe215&devicetype=desktop&pguid=8d5711736aa6359e44c347f2&viewguid=TNCn1ELOPJ-mn8GfHYaAHTg5X5-pprCSxvyb&destUrl=http://software-files-a.cnet.com/s/software/13/85/18/.../DownloadApp_1_8_0_209r_Setup.exe

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to phx1-dw-cbsi-xw-lb.cnet.com  (64.30.224.172:80)

Remove downloadapp_1_8_0_209r_setup.exe - Powered by Reason Core Security