icreinstall_microsoft-word-2013.exe

Destiny Dream S.A.

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_microsoft-word-2013.exe, “Installer Setup ” by Destiny Dream S.A has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn.directinstallershub.com and multiple other hosts. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Installer   (signed by Destiny Dream S.A.)

Product:
Installer

Description:
Installer Setup

Version:
2.5.2.5

MD5:
e4afd39e3f8f6f82d43991e920b807b2

SHA-1:
b3f31db23f2a7183a5780dbd1f06b3e0fd385e45

SHA-256:
5cbce67ddc6930faaa8f08e2976ab6b0dd107191b5cb7229c40ea45c82e14ef5

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/19/2024 3:57:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.DestinyDreamSA.Installer (M)
16.1.13.9

File size:
858.3 KB (878,928 bytes)

Product version:
4.3.2

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_microsoft-word-2013.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/19/2015 7:14:38 PM

Valid to:
3/19/2016 7:14:38 PM

Subject:
CN=Destiny Dream S.A., O=Destiny Dream S.A., L=Clarens, C=CH

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00CE0712FA54C44753

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:anoiz7gcv4TutnOJdZzKX955lp3Y98NTg:aoekXutnQZzKt55lpbM

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9145

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file icreinstall_microsoft-word-2013.exe has been seen being distributed by the following 2 URLs.

http://cdn.directinstallershub.com/c?x=Fx aDCFnOIR/RIU9ubticdnEaKNd6DQKTW5tlI/s/0I=&c=oo646FXNGCndGOhSuV136kSBmjXNZRKb71mPAJBJAvLAsAWZSz7WhDyYMPHlybA9I8EJtrLMZSGKt2o7vXRxX/SS7M6u /CduKaW0LvSokArrDsg9kQ9VS1vEGqIrJvcJwabG2T6VnV1i7lzghdslQ==&downloadAs=microsoft-word-2013.exe&fallback_url=http://office.microsoft.com/en-001/.../

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

Remove icreinstall_microsoft-word-2013.exe - Powered by Reason Core Security