downloader_for_alcohol120_fe_2.0.3.8703.exe

Nore

The application downloader_for_alcohol120_fe_2.0.3.8703.exe, “Nore Setup ” has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.firefilesdata.com and multiple other hosts.
Product:
Nore

Description:
Nore Setup

Version:
4.0.4.8

MD5:
f927648c77bd3855bb2104a003f1d45d

SHA-1:
89a24260fd864945dcd8c197d06b1bd881aea50b

SHA-256:
d836e5b8401ac916fab592c9137aa319a87864fcb65ad722382afb279c646837

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/16/2024 6:38:00 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.InstallCore.666
9.0.1.05190

ESET NOD32
Win32/InstallCore.ACY.gen potentially unwanted application
8.0.319.0

Reason Heuristics
PUP.InstallCore.EST (M)
16.3.10.13

File size:
1 MB (1,067,249 bytes)

Product version:
1.3.1

Copyright:
Soft Web

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:9aQ0/u7klqW6KY4rOt8wtTt3Sd7ElBGLcuvMts:9qiyqiYHtnRm7ElBe9vM+

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file downloader_for_alcohol120_fe_2.0.3.8703.exe has been seen being distributed by the following 50 URLs.

http://www.firefilesdata.com/WVl6OTRQVEZrZERKak5TVXlRa2RXSlRKQ2FTVXlSbUZHYWtKYVFrODFaWHAxZUVvNGJWWWxNa1l4YTNaQ1JESlRaSEZLU0dWUlp5VXpSQ1pqUFhCQlFTVXlSbkpDWVVkTmVrMUdTVk5PYlVkUk4zSm1VVkJwZWtFelRHVm1OemhoUnpjNFIyMXNaa2hrZFNVeVJreEhRME5RUm1OWlZFOUVTMHBOTjJkdFVUSlZlVXB1ZFRGTU9FZG9UekJKU21SYUpUSkdlbVpwVW1RMVZEVTRlVkU0YkVaNE1rUkJaREF5UjBNMVIwSlphV2tsTWtJNE5uUkZiMFoxVjJSUE5VSTFXbHBKYVhjbVpHOTNibXh2WVdSQmN6MWtiM2R1Ykc5aFpHVnlYMlp2Y2w5QmJHTnZhRzlzTVRJd1gwWkZYekl1TUM0ekxqZzNNRE11WlhobA==

http://www.firefilesdata.com/c?x=xvsu69OZn1SV 26oG60xInozMfOePP6VnXuTQIO3Hak=&c=cfWzL/NxU4KWYI/hFPbG20xrBr jOL0vcJmmZVNzg/.../nmOUY1 pcpV4VaYFT&downloadAs=downloader_for_Alcohol120_FE_2.0.3.8703.exe

http://www.firefilesdata.com/WVl6OTRQVzV6UmxkR1VHRmFlRGR5TkV0R09TVXlRalpSV0RBd2RXRTNaR0pyUm5oUlRGTk9PWFZuVG5RNWRrZ3dZeVV6UkNaalBWQTBTMmNsTWtaSk4yTXplV1oyUnpObkpUSkdWM1IxVmpWRlMzWnRSblI0TjJ0eU9YVm1UU1V5UWxWb2JERkxTbXhvV2pGeWNUWm9iRFZQU25FeGVVazRZMjVHZGxwdGVVdFVaa0UxZVhOUFRGQldiR1JYVFZCdVFsQkZXWGwzTldKV1JYUkJjRWx1SlRKR1IwcFdWWFI0VHlVeVFrNDFhbTgzVERKNVpsZExkVTVZYkRrd1kyZDVlU1prYjNkdWJHOWhaRUZ6UFdSdmQyNXNiMkZrWlhKZlptOXlYMEZzWTI5b2Iyd3hNakJmUmtWZk1pNHdMak11T0Rjd015NWxlR1U9

Latest 30 of 62 download URLs

Remove downloader_for_alcohol120_fe_2.0.3.8703.exe - Powered by Reason Core Security