icreinstall_jse_install_app-1437712456580.exe

Web Installer

MaxPlatform (Fried Cookie Ltd)

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_jse_install_app-1437712456580.exe, “Web Installer Setup ” by MaxPlatform (Fried Cookie) has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Web application   (signed by MaxPlatform (Fried Cookie Ltd))

Product:
Web Installer

Description:
Web Installer Setup

Version:
4.1.2.2

MD5:
e54a0e6bc12f2adbc9fc2bdf6b46a1ff

SHA-1:
02858261b48532b6a8cd4197365ba38b24ab10a3

SHA-256:
340bb00a0468c9272d5c69dfd10d088c8442ec89ae9ba2a68fee4b8fd4d7feea

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/18/2024 2:47:08 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

AVG
Generic
2016.0.3001

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.15830

Bkav FE
W32.HfsAdware
1.3.0.6979

Comodo Security
Application.Win32.InstallCore.DQT
22898

Dr.Web
Trojan.InstallCore.864
9.0.1.0242

ESET NOD32
Win32/InstallCore.AAJ potentially unwanted (variant)
9.12019

K7 AntiVirus
Adware
13.207.16740

Malwarebytes
v2015.08.30.08

Panda Antivirus
PUP/Multitoolbar
15.08.30.08

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.InstallCore.Installer.Installer (M)
15.8.30.20

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
42462

File size:
856.7 KB (877,272 bytes)

Product version:
3.5.7

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_jse_install_app-1437712456580.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/27/2015 7:42:25 PM

Valid to:
4/27/2016 7:42:25 PM

Subject:
CN=MaxPlatform (Fried Cookie Ltd), O=MaxPlatform (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121507E6BDD0438A3C158F873DCAA10634D

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:r1VGAQ+5T5t5XY14PeCappFaT77qTb5z0DLHHkZy8t30E/KfsgNSr0fwT2+pHTEM:r1VBhp5zXY10ap7a7KYDLn3eKkDS8NTn

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9102

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)