icreinstall_movie_studio_platinumsetup_v1.0.3.5737_nooffer.exe

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_movie_studio_platinumsetup_v1.0.3.5737_nooffer.exe has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the installCore installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
MD5:
e8127809c021518f5973cc66cad8ef1d

SHA-1:
55fcf53925660bf1697edf8e4ea3722efecc399b

SHA-256:
5439c0de0c5d0df99bc27f46492b2e68f050bdd43e83623d1a999ae4cf509acb

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 2:40:37 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.170.84

ESET NOD32
Win32/InstallCore.AZ potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.W.gen
4.6.5.141

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14830

File size:
1.6 MB (1,665,024 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_movie_studio_platinumsetup_v1.0.3.5737_nooffer.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:X6/sQfR874Pebdxz78mlIU5dmLwqO3ccnWYL4lVRJIQmgzfmCArVWs5IFrWH:KUQEIeRxz7838dmLYBnWYeIQmglArtC

Entry address:
0xD6870

Entry point:
55, 8B, EC, 83, C4, F0, B8, 74, E1, 41, 00, E8, 3F, E8, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.2416

Developed / compiled with:
Microsoft Visual C++

Code size:
869.5 KB (890,368 bytes)

The file icreinstall_movie_studio_platinumsetup_v1.0.3.5737_nooffer.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)