greengamesandham_unlockgames.exe

Installer

OpenInstall, Inc.

The application greengamesandham_unlockgames.exe by OpenInstall has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from 98acdc60cb7e28f9e56a-c9c8355414dceb2e62093c8746e20714.r4.cf2.rackcdn.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
OpenInstall   (signed by OpenInstall, Inc.)

Product:
Installer

Version:
1,18,0,2771

MD5:
add4279a389feb8552bc065ee0095085

SHA-1:
be8706f2c0785e0e58c6f95d53c7c6a52ee6e664

SHA-256:
d5ee3d493c0bdbdb081b28f169c4ddd2fe306e5e8a4a0f097494efbcf312d1ea

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Includes Open Install, an installer which bundles legitimate programs with offers for additional 3rd-party applications that may be unwanted by the user.

Analysis date:
4/26/2024 9:47:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OpenInstall.Installer (M)
15.11.15.8

File size:
358.3 KB (366,896 bytes)

Product version:
1,18,0,2771

Copyright:
Copyright © 2012

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\greengamesandham_unlockgames.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/20/2011 7:00:00 PM

Valid to:
1/24/2013 7:00:00 AM

Subject:
CN="OpenInstall, Inc.", O="OpenInstall, Inc.", L=San Francisco, S=California, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07AE9941492080181D2477353500DE05

File PE Metadata
Compilation timestamp:
7/27/2012 8:32:03 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:DVsCNZZi8bDZwxj20RnV6uYcl2mUCtUxjNStsDs9CQRzgEiO:DVsCNLiGZ2jlV6uBUxhStsDlQRcO

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, 18, 04, 00, 00, 53, 56, 57, BE, A4, 30, 40, 00, 8D, BD, E8, FB, FF, FF, A5, A5, A5, 6A, 7E, 66, A5, 59, 33, C0, 8D, BD, F6, FB, FF, FF, F3, AB, 66, AB, BB, 04, 01, 00, 00, 53, 8D, 85, E8, FB, FF, FF, 50, FF, 15, 5C, 30, 40, 00, 66, 83, A5, F0, FD, FF, FF, 00, 33, C0, B9, 81, 00, 00, 00, 8D, BD, F2, FD, FF, FF, F3, AB, 66, AB, 8D, 85, F0, FD, FF, FF, 50, 8D, 85, E8, FB, FF, FF, 50, C7, 45, F8, FD, FF, FF, FF, E8, 0F, 01, 00, 00, 84, C0, 59, 59, 74, 15, 8D, 75, F8, 8D, BD, F0, FD, FF, FF...
 
[+]

Entropy:
7.4895

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file greengamesandham_unlockgames.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove greengamesandham_unlockgames.exe - Powered by Reason Core Security