icreinstall_facemoods.exe

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_facemoods.exe has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the installCore installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from i.facemoods.com and multiple other hosts. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
MD5:
21d0799c63134365ec77b9a44a1cc3d5

SHA-1:
c059cb36ecbbd60b504be74f886980e28e4b26f8

SHA-256:
45180324e8f680adf24888d90e724b8ca08b194b337d1de9d6214ccbbaca9778

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 4:01:44 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.123.202

avast!
Win32:FunMood-A [PUP]
2014.9-131228

Bkav FE
W32.Clod534.Trojan
1.3.0.4613

ESET NOD32
Win32/InstallCore.BH (variant)
7.9257

F-Prot
W32/InstallCore.G4.gen
v6.4.7.1.166

IKARUS anti.virus
SoftwareBundler
t3scan.2.2.29

K7 AntiVirus
Trojan
13.175.10750

File size:
633.6 KB (648,760 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_facemoods.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:iwruSejgcwgQzJq4L29WHafI0QklEybZrT9Xqq1NxezBdmzu52EOIl6+pL:iwrSjgcrk/LuRq85ZXqq1NE9dYu5a+5

Entry address:
0x131AD0

Entry point:
60, BE, 00, D0, 49, 00, 8D, BE, 00, 40, F6, FF, C7, 87, 10, 47, 0E, 00, 74, CB, 28, 9C, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
596 KB (610,304 bytes)

The file icreinstall_facemoods.exe has been seen being distributed by the following 5 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

Remove icreinstall_facemoods.exe - Powered by Reason Core Security