google_earth_tr.exe

Symbolicom Holdings Ltd

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application google_earth_tr.exe by Symbolicom Holdings has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from safe.to.download.downloadastro.com.
Publisher:
Symbolicom Holdings Ltd  (signed and verified)

MD5:
9a897f76d2d37525c53c4e0900575693

SHA-1:
4343ece7e6d4fd02716d01b870f67eeb272bd207

SHA-256:
afceebf13b62b3d3b1ceb7dfc465b2c6d72b24fbbd5dea9fa77c17a1bf694d63

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/25/2024 7:34:25 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
7.11.158.148

avast!
Win32:Adware-gen [Adw]
140617-1

AVG
Trojan horse Ransomer.DBB
2014.0.3986

Comodo Security
ApplicUnwnt
18771

Dr.Web
Trojan.MulDrop5.10078
9.0.1.05190

ESET NOD32
Win32/InstallCore.JE.gen potentially unwanted application
7.0.302.0

Malwarebytes
v2014.07.05.08

Reason Heuristics
PUP.SymbolicomHoldings.P
14.7.5.7

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14703

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
Threat.4788237
29708

Zillya! Antivirus
Trojan.Kryptik.Win32.492870
2.0.0.1845

File size:
697.9 KB (714,624 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Turkish (Turkey)

Common path:
C:\users\{user}\downloads\google_earth_tr.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/8/2014 2:00:00 AM

Valid to:
1/9/2015 1:59:59 AM

Subject:
CN=Symbolicom Holdings Ltd, OU=Symbolicom, O=Symbolicom Holdings Ltd, STREET=Trident Cyprus, STREET=115 Griva Digeni Avenue Trident Centre, STREET=Limassol, L=Limassol, S=Cyprus, PostalCode=3101, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C4B90F930A0BA04B111E671526916207

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:1vpghu68Okv8a8I2E7DFouu9TSfPoGYdF0nqk203TkyEe2bOFbWRMUJDMy1TXzHC:1vmhuBYjgDjaYGfQH203d/+f2UDTXz

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file google_earth_tr.exe has been seen being distributed by the following URL.

Remove google_earth_tr.exe - Powered by Reason Core Security