icreinstall_business card designer plus 11.0.0.0.exe

Generic Internet

Ringier Axel Springer Polska Sp z o.o.

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_business card designer plus 11.0.0.0.exe, “Generic Internet Setup ” by Ringier Axel Springer Polska Sp z o.o has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Program Web   (signed by Ringier Axel Springer Polska Sp z o.o.)

Product:
Generic Internet

Description:
Generic Internet Setup

MD5:
aff07a89658994bc1501d6083dd7bbb2

SHA-1:
0282551533f120bc6f94032aa486cebc00798f3a

SHA-256:
9255576574acb3bf721fedd4b2eb3fe7ba6406c1fb5b9b7ab8fe7ad6a60abb57

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
10/24/2020 5:07:52 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore (M)
16.11.7.2

File size:
962.7 KB (985,776 bytes)

Product version:
4.1

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_business card designer plus 11.0.0.0.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 6:05:16 PM

Valid to:
4/20/2016 1:59:59 PM

Subject:
CN=Ringier Axel Springer Polska Sp z o.o., O=Ringier Axel Springer Polska Sp z o.o., L=Warszawa, C=PL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112124E7511A3CC4B3EC5ECEA81705B2D037

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:MXMpbjai5w3gnt1oFoSefqkP1DBX3cyDVk+xuACgkfUa:MXMA3s1nZ19XjpLxvChMa

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)