email_verifier_demo.exe

GSA Email Verifier

Sven Bansemer and Thomas Scheel GbR

The application email_verifier_demo.exe, “GSA Email Verifier Setup ” by Sven Bansemer and Thomas Scheel GbR has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from email.verifier.gsa-online.de.
Publisher:
GSA Software   (signed by Sven Bansemer and Thomas Scheel GbR)

Product:
GSA Email Verifier

Description:
GSA Email Verifier Setup

MD5:
e0522d81494c24cbc1289e9f184b5297

SHA-1:
6483e7dad73250b73f2ed9fb019d6f0693d9fc68

SHA-256:
195f3e5bc4c3425f4b9104d2d5a9cdc7085d05f796bad04361b22af01464213e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/18/2024 11:07:58 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.4.16

File size:
10.7 MB (11,193,240 bytes)

Product version:
2.66

Copyright:
© 2012 GSA Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\email_verifier_demo.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/1/2012 8:00:00 PM

Valid to:
11/2/2013 7:59:59 PM

Subject:
CN=Sven Bansemer and Thomas Scheel GbR, O=Sven Bansemer and Thomas Scheel GbR, STREET=Dierkower Damm 29, L=Rostock, S=Outside United States, PostalCode=18146, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CE6C72339BF37486698C2CD38A8EDCBB

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:0NxQ+8diw8Ls1OVpSZPoSfoM0Om9zEH4QsXaIJipk526X6aVnWSKf28tE:0NxQ+YypaTfR0OmNEbneuK6aqfJtE

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9997

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file email_verifier_demo.exe has been seen being distributed by the following URL.

http://email.verifier.gsa-online.de/.../email_verifier_demo.exe

Remove email_verifier_demo.exe - Powered by Reason Core Security