grand-theft-auto-san-andreas-patch-101-baixaki-32-bits.exe

The application grand-theft-auto-san-andreas-patch-101-baixaki-32-bits.exe has been detected as a potentially unwanted program by 18 anti-malware scanners. The program is a setup application that uses the installCore installer, however the file is not signed with an authenticode signature from a trusted source. According to Microsoft Security Essentials, the software includes a bundle of the DealPly adware which is installed on a user's PC during setup using the InstallCore platform. The file has been seen being downloaded from cf.baixaki.com.br.
MD5:
91535e752eed6b5b68cd5198144620b9

SHA-1:
9db9dd9ef3c013572f593272e4ad7ce6a5a12854

SHA-256:
1b0fd1ce1b0d363238904ed3ad31bfea9b52ce73cfaf311056a61aad7a5ddb47

Scanner detections:
18 / 68

Status:
Potentially unwanted

Explanation:
This software bundler installs other potentially unwanted software, including DealPly. Which includes offers in a user's web browser which state they are "Powered by DealPly".

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 9:55:45 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/InstallBai.A
7.11.115.36

Bitdefender
Adware.Generic.625043
1.0.20.75

Comodo Security
ApplicUnwnt
17316

Dr.Web
Adware.InstallCore.122
9.0.1.015

Emsisoft Anti-Malware
Adware.Generic.625043
8.16.01.15.08

ESET NOD32
Win32/InstallCore.BL
10.9085

Fortinet FortiGate
W32/InstallCore.BL
1/15/2016

F-Prot
W32/InstallCore.R.gen
v6.4.7.1.166

F-Secure
Adware.Generic.625043
11.2016-15-01_6

G Data
Adware.Generic.625043
16.1.22

IKARUS anti.virus
SoftwareBundler
t3scan.2.2.29

Malwarebytes
v2016.01.15.08

McAfee
Artemis!91535E752EED
5600.6520

Microsoft Security Essentials
1.163.1557.0

MicroWorld eScan
Adware.Generic.625043
17.0.0.45

Reason Heuristics
PUP.InstallCore.Bundler (M)
16.1.15.8

SUPERAntiSpyware
9384

VIPRE Antivirus
InstallCore
23632

File size:
622.1 KB (637,016 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\grand-theft-auto-san-andreas-patch-101-baixaki-32-bits.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:CpyMJfs2yLl1m6jIgjS4HSU6us2WhX33/NNWbIZWLVqNVS2eXjoorfc2M:CpyMJfspJ4T40uIV33lNWyWANVUzDrfE

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file grand-theft-auto-san-andreas-patch-101-baixaki-32-bits.exe has been seen being distributed by the following URL.