icreinstall_acebyteutilities.exe

META., JSC

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_acebyteutilities.exe by META., JSC has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
META., JSC  (signed and verified)

MD5:
436c0533d273ce1ffb523ffaef384dbb

SHA-1:
1564d504f7de69f2505dd04e9cbae8aa4cf64c96

SHA-256:
569c5237d105f37d3babb934001e6321c6b19f7a3072471c2fe3c973a8bd283c

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 5:55:41 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.197.16

AVG
InstallC
2015.0.3254

ESET NOD32
Win32/InstallCore.PY potentially unwanted application
7.0.302.0

K7 AntiVirus
Trojan
13.188.14395

Reason Heuristics
PUP.METAJSC.CC
14.12.21.8

Sophos
PUA 'Install Core Click run software'
5.09

VIPRE Antivirus
Threat.4150696
35418

File size:
790.4 KB (809,344 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temp\icreinstall_acebyteutilities.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/6/2013 8:00:00 AM

Valid to:
11/6/2016 7:59:59 AM

Subject:
CN="META., JSC", O="META., JSC", STREET="B49, Duy Tan Street, Dich Vong Hau Ward, Cau Giay District", L=Hanoi, S=Hanoi, PostalCode=10000, C=VN

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D08397D094A2AC46809B3100D8A03A0A

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:lAFa2QfFBYg8aaZpPGEOaANH4u4rREokYJhuZGnzp7jOS0lnxY7vQS7uQyW:lAFvS8aaZpPGEOaxuVihu4nz5jgwQol

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8397

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_acebyteutilities.exe - Powered by Reason Core Security