icreinstall_cat mario downloader - jalantikus.exe

Finibeline

PT MP Games

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_cat mario downloader - jalantikus.exe, “Finibeline Setup ” by PT MP Games has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.safeapplicationsfun.com and multiple other hosts. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
PT MP Games  (signed and verified)

Product:
Finibeline

Description:
Finibeline Setup

MD5:
f766dfbc8ce2943e046f3b1c72df1ce9

SHA-1:
a3c05a7c219d7556bbdd5667529c252ee604f483

SHA-256:
86bf5b9f83bc65fbaad01e5e6721cfd794b72c372161f7962a5a4874e2392ada

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/21/2024 8:42:35 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.PTMPGame.Installer (M)
16.4.30.6

File size:
1.1 MB (1,148,744 bytes)

Product version:
2.1

Copyright:
Lite

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_cat mario downloader - jalantikus.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/20/2016 5:49:25 PM

Valid to:
1/20/2017 5:49:25 PM

Subject:
CN=PT MP Games, O=PT MP Games, S=Jakarta, C=ID

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112196D38C2D01B48C24B0EE5080C33055F9

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:HVUleZyqJQtNmhPnh8FPXAK3WoxItNmXy6h+NP+fEzqhjoTX:HVAeMqoNEPhgXAaWoSNmANwj4X

Entry address:
0xAA98

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 2E, 86, FF, FF, E8, 35, 98, FF, FF, E8, 9C, 9B, FF, FF, E8, B7, 9F, FF, FF, E8, 56, BF, FF, FF, E8, ED, E8, FF, FF, E8, 54, EA, FF, FF, 33, C0, 55, 68, 69, B1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 32, B1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, D0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, C2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, 24, 93, FF, FF, 8D, 55, F0, 33, C0, E8, 66, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.6920

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
40.5 KB (41,472 bytes)

The file icreinstall_cat mario downloader - jalantikus.exe has been seen being distributed by the following 2 URLs.

http://www.safeapplicationsfun.com/c?x=IDpvWj9NCenkLibTGvzglOWwoH05kcv8ZJ7B7PmXPH0=&c=bEBsk58V7RABtEILKR60Pp8inD1ugIwp/Xh6ttAdRKen0Z98mUknhZsXLcbraKZSK5JVODeLng1PdK/gFxchJOw8p5xoQGCSkW Iju8d5TL0JQMV56fWvuLLNtvDOxbmtcDXE WMynV8z7Ro1NdwZA==&e=0&downloadAs=Cat Mario Downloader - JalanTikus.exe&fallback_url=http://files.jalantikus.com/dde/3948/.../Cat_Mario_4_JalanTikus.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)