icreinstall_icreinstall_setup.exe

Volonet Ltd

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_icreinstall_setup.exe by Volonet has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Volonet Ltd  (signed and verified)

MD5:
7a4f58fbb00df51913e7d74fc0669010

SHA-1:
c76a9a944833de1c9cb0c5393b844cc599dcd9e3

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Analysis date:
4/16/2024 9:52:13 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.9.11.19

File size:
1 MB (1,078,360 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\icreinstall_icreinstall_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/11/2012 7:00:00 AM

Valid to:
11/26/2013 6:59:59 AM

Subject:
CN=Volonet Ltd, O=Volonet Ltd, STREET=hazfira 19, L=Tel Aviv, S=Israel, PostalCode=67778, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D9EB879A7F4ADB713BB56F5D9EA449DA

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:g0zN4AcLUFL3/cU9iJRc5HjFWTaXuc8d57Z8PoL+tTl7E:gIT9i2joTa+4gSH4

Entry address:
0xC1C00

Entry point:
55, 8B, EC, 83, C4, F0, B8, 94, B5, 40, 00, E8, 20, DD, FF, FF, 83, C4, F8, 8B, D8, 8B, FB, 8B, 32, 8B, 43, 08, 3B, F0, 72, 6C, 8B, CE, 03, 4A, 04, 8B, E8, 03, 6B, 0C, 3B, CD, 77, 5E, 3B, F0, 75, 1B, 8B, 42, 04, 01, 43, 08, 8B, 42, 04, 29, 43, 0C, 83, 7B, 0C, 00, 75, 44, 8B, C3, E8, 35, FF, FF, FF, EB, 3B, 8B, 0A, 8B, 72, 04, 03, CE, 8B, F8, 03, 7B, 0C, 3B, CF, 75, 05, 29, 73, 0C, EB, 26, 8B, 0A, 03, 4A, 04, 89, 0C, 24, 2B, F9, 89, 7C, 24, 04, 8B, 12, 2B, D0, 89, 53, 0C, 8B, D4, 8B, C3, E8, D0, FE, FF, FF...
 
[+]

Entropy:
6.9425

Developed / compiled with:
Microsoft Visual C++

Code size:
788 KB (806,912 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

Remove icreinstall_icreinstall_setup.exe - Powered by Reason Core Security