icreinstall_internetexplorerupdatesetup.exe

File.org

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_internetexplorerupdatesetup.exe by File.org has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. With this installer, users are expecting to download Internet Explorer but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
File.org  (signed and verified)

MD5:
dcb5c499196f11fa180cf7a283c758f8

SHA-1:
fa216973a80f4d79abd41114ab3f13da04d57429

SHA-256:
631a3fda9627541cb0e32f252a09d2a7e897b3c6b642e37bf19437cfade469ed

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/27/2024 12:13:07 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.Fileorg.Installer (M)
16.2.9.5

File size:
955.3 KB (978,192 bytes)

Product version:
1.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_internetexplorerupdatesetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/25/2014 5:30:00 AM

Valid to:
4/26/2015 5:29:59 AM

Subject:
CN=File.org, O=File.org, STREET=Bysoestrade 2B st., L=Holbaek, S=N/A, PostalCode=4300, C=DK

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E2D23668FD70A6AD497F37619358D967

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:dH9p5KSxUwuUbQw6LP71SeanBSvdqHuMgXb5dNamqbP6UPqMCz/X3olcUl9jctNn:dH9vKSlQd779aniIGCb6UE/+c+Yp

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9290

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_internetexplorerupdatesetup.exe - Powered by Reason Core Security