icreinstall_jdownloadersetup_ch3.exe

AppWork GmbH

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_jdownloadersetup_ch3.exe by AppWork GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
AppWork GmbH  (signed and verified)

MD5:
f95d23d977ab3af51d9e32d1847d7a0c

SHA-1:
2716ecc4fd2a1556bbc8fab9004b42bfdcf74587

SHA-256:
8a71a98561be838d051d6b251337d48b6e6deb88cdd6b22c61998d09d0d1646e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Analysis date:
4/25/2024 5:26:37 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.Installer (M)
16.2.15.19

File size:
1012.1 KB (1,036,416 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_jdownloadersetup_ch3.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
3/1/2011 8:00:48 AM

Valid to:
3/1/2014 8:00:41 AM

Subject:
E=e-mail@appwork.org, CN=AppWork GmbH, O=AppWork GmbH, L=Fürth, S=Bavaria, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012E71E7355C

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ZGPiyDudE5mNcK6NU0IfSh76+v4Nn8whIITk73:ZGP2u5OCXIfShj4N8wh3T

Entry address:
0xC1D3C

Entry point:
55, 8B, EC, 83, C4, F0, B8, 3C, 8F, 40, 00, E8, 22, E3, FF, FF, 00, 8B, C0, FF, 25, 84, 41, 47, 00, 8B, C0, FF, 25, 80, 41, 47, 00, 8B, C0, FF, 25, 7C, 41, 47, 00, 8B, C0, FF, 25, 78, 41, 47, 00, 8B, C0, FF, 25, 74, 41, 47, 00, 8B, C0, FF, 25, 70, 41, 47, 00, 8B, C0, FF, 25, 6C, 41, 47, 00, 8B, C0, FF, 25, 68, 41, 47, 00, 8B, C0, FF, 25, 64, 41, 47, 00, 8B, C0, FF, 25, 60, 41, 47, 00, 8B, C0, FF, 25, 5C, 41, 47, 00, 8B, C0, FF, 25, 58, 41, 47, 00, 8B, C0, FF, 25, C4, 41, 47, 00, 8B, C0, FF, 25, 54, 41, 47...
 
[+]

Entropy:
6.9265

Developed / compiled with:
Microsoft Visual C++

Code size:
788 KB (806,912 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_jdownloadersetup_ch3.exe - Powered by Reason Core Security