downloadsetup.exe

Setup

Artua Vladislav

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions which inject ads in the browser. The application downloadsetup.exe by Artua Vladislav has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the WebPick InstalleRex installer. The file has been seen being downloaded from premiumstorage.info. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
Premium  (signed by Artua Vladislav)

Product:
Setup

Description:
Installer

Version:
2011.12.13.2110

MD5:
ec988ba0c8f4bfd7e90aec0724912dce

SHA-1:
894646d14facf7165922de3c86ded69afb968392

SHA-256:
26246aa9f1a0c7ff7cb344d7fa1b760b363b9360f901a423f9b4a4f999d0b835

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 9:36:10 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick.ArtuaVladislav.Bundler (M)
15.7.15.11

File size:
238.1 KB (243,768 bytes)

Product version:
1.0

Copyright:
Copyright © 2010 Premium

File type:
Executable application (Win32 EXE)

Bundler/Installer:
WebPick InstalleRex

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\downloadsetup.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/14/2011 8:00:00 PM

Valid to:
3/14/2012 7:59:59 PM

Subject:
CN=Artua Vladislav, O=Artua Vladislav, STREET=haRav Dangur 22, L=Bnei Braq, S=Israel, PostalCode=51281, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
302242B18FB354EA399140DBBA22B786

File PE Metadata
Compilation timestamp:
12/1/2011 6:07:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:3R+4UQ/l+yaA3loTp4fIRX1PJVuHusG5mlab8jm:3RFUQ/FboTyfIRRJVuHusamlaYjm

Entry address:
0x1513

Entry point:
55, 8B, EC, 81, EC, 38, 0B, 00, 00, 53, 56, 57, 8D, 85, E0, FE, FF, FF, 50, C7, 85, E0, FE, FF, FF, 14, 01, 00, 00, FF, 15, 74, 30, 40, 00, 85, C0, 74, 11, 33, C0, 83, BD, F0, FE, FF, FF, 01, 0F, 94, C0, A3, 00, 40, 40, 00, 33, F6, 66, 89, B5, C8, F4, FF, FF, 89, 75, F4, 89, 75, FC, FF, 15, 70, 30, 40, 00, A3, 08, 40, 40, 00, FF, 15, 6C, 30, 40, 00, 89, 45, F8, 68, 04, 01, 00, 00, 8D, 85, D8, FC, FF, FF, 50, 56, FF, 15, 68, 30, 40, 00, 85, C0, 75, 22, FF, 15, 64, 30, 40, 00, 50, 68, D0, 33, 40, 00, E8, EA...
 
[+]

Entropy:
7.9350

Developed / compiled with:
Microsoft Visual C++

Code size:
8 KB (8,192 bytes)

The file downloadsetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

Remove downloadsetup.exe - Powered by Reason Core Security