ibsvc.exe

Softango Download Manager

Softango Inc.

This is the Performersoft setup installer. The application ibsvc.exe by Softango has been detected as adware by 25 anti-malware scanners. The program is a setup application that uses the InstallBrain installer. It runs as a windows Service named “Updater Service”. According to AVG, this software downloads additional adware offers during setup. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
Softango  (signed by Softango Inc.)

Product:
Softango Download Manager

Version:
15.9.28.27

MD5:
5c96a5cd5cc2cd4890bb34f06e96d84e

SHA-1:
b5623d92f2e7bdf4e0cc9afd0f01784877fae2bb

SHA-256:
c76eca8576bd80a850c06f39c0d5213d2797eaafd45a47dda43e07309347ca94

Scanner detections:
25 / 68

Status:
Adware

Explanation:
Uses the InstallBrain monetization platform from iBario to deliver bundled adware both search toolbars and PC optimizers from Performersoft.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 9:57:04 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.InstallBrain.A
355

Agnitum Outpost
Adware.BrainInst
7.1.1

AhnLab V3 Security
PUP/Win32.BrainInst
2014.08.21

Avira AntiVirus
APPL/InstallBrain.Gen
7.11.168.126

avast!
Win32:Installer-O [PUP]
2014.9-160215

AVG
Trojan horse Downloader.Generic13
2017.0.2833

Bitdefender
Application.Bundler.InstallBrain.A
1.0.20.230

Comodo Security
Application.Win32.InstallBrain.AY
19262

Dr.Web
Adware.Downware.1295
9.0.1.046

ESET NOD32
Win32/InstallBrain.AA potentially unwanted application
10.7.0.302.0

F-Prot
W32/IBrain.D.gen
v6.4.6.5.141

G Data
Application.Bundler.InstallBrain
16.2.24

IKARUS anti.virus
PUA.Filescout
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.176.11210

Kaspersky
not-a-virus:AdWare.Win32.BrainInst
14.0.0.660

Malwarebytes
PUP.Optional.Softango.A
v2016.02.15.12

Microsoft Security Essentials
Threat.Undefined
1.181.222.0

MicroWorld eScan
Application.Bundler.InstallBrain.A
17.0.0.138

NANO AntiVirus
Trojan.Win32.Downware.cqxpgy
0.28.2.61721

Quick Heal
TrojanDownloader.Brantall.A5
2.16.14.00

Reason Heuristics
PUP.Performersoft.Softango.Bundler (M)
16.2.15.0

Sophos
InstallBrain
4.98

Vba32 AntiVirus
AdWare.BrainInst
3.12.26.3

VIPRE Antivirus
Threat.4759033
32210

Zillya! Antivirus
Adware.BrainInst.Win32.63
2.0.0.1897

File size:
540.8 KB (553,752 bytes)

Product version:
15.9.28.27

Copyright:
Copyright 2012

Original file name:
Softango_Download_Manager.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallBrain

Language:
English (United States)

Common path:
C:\ProgramData\ibupdaterservice\ibsvc.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
3/29/2013 5:18:12 PM

Valid to:
3/29/2016 6:18:12 PM

Subject:
CN=Softango Inc., O=Softango Inc., L=Beaverton, S=OR, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
07B9F930CBBB4F

File PE Metadata
Compilation timestamp:
7/1/2013 12:07:18 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:vS6yXhEVau22KdKMIcTJae+Lh6ZaOUrpk+5J/BVL:aBeKdKCVae+LhElamo/L

Entry address:
0x934D

Entry point:
E8, AD, 41, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, A8, D4, 41, 00, 00, 75, 18, E8, F8, 39, 00, 00, 6A, 1E, E8, 42, 38, 00, 00, 68, FF, 00, 00, 00, E8, 41, 25, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, A8, D4, 41, 00, FF, 15, 44, 60, 41, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, A4, D4, 41, 00, 74, 0D, 53, E8, 91, 18, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, 63, 18, 00, 00, 89, 30, E8, 5C, 18, 00, 00, 89...
 
[+]

Entropy:
7.7096  (probably packed)

Code size:
81.5 KB (83,456 bytes)

Service
Display name:
Updater Service

Service name:
IBUpdaterService

Type:
Win32ShareProcess


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove ibsvc.exe - Powered by Reason Core Security