icreinstall_conquista.exe

REDACCENIR SL

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_conquista.exe by REDACCENIR SL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
REDACCENIR SL  (signed and verified)

MD5:
ad9367892eaf79f83daa78796d27de09

SHA-1:
1db22341552d1ce0a695549036d9d6a3794d4570

SHA-256:
c6147f001b4d27ae602ca3c741065b9e288d1d409887854b3a8b49d3229365bb

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 10:17:54 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.REDACCENIR.Bundler (M)
16.2.11.23

File size:
602.1 KB (616,568 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_conquista.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/22/2011 6:00:00 PM

Valid to:
12/22/2012 5:59:59 PM

Subject:
CN=REDACCENIR SL, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=REDACCENIR SL, L=Terrassa, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71215C0E2FF8F33A61438B1BB7D0D7D3

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:iiHS7FPQ0gTNgjoEIYnONlDZW/zM387a3ourmH/c3PFAcJxnCrBY0XmgOkSbAsUy:iJPQzij8WbC8Ob6HE3PvcBYqHBSssJ

Entry address:
0x118D00

Entry point:
60, BE, 00, D0, 48, 00, 8D, BE, 00, 40, F7, FF, C7, 87, 10, 27, 0C, 00, 59, 3A, A4, 2D, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8259

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
560 KB (573,440 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_conquista.exe - Powered by Reason Core Security