icreinstall_mp3gain.exe

REDACCENIR SL

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_mp3gain.exe by REDACCENIR SL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
REDACCENIR SL  (signed and verified)

MD5:
8fc8e19a9d596d37fc807d235998e466

SHA-1:
4aa4db189233b39cd9b5bcc5037c3b658da8d72a

SHA-256:
2a11c5e4837810a7757fef6d45eff342d9c7730026598ec3b1dff0ee9bb37b88

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/24/2024 12:36:32 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.REDACCEN.Bundler
17.2.23.0

File size:
1.1 MB (1,129,592 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_mp3gain.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/22/2011 10:00:00 PM

Valid to:
12/22/2012 9:59:59 PM

Subject:
CN=REDACCENIR SL, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=REDACCENIR SL, L=Terrassa, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71215C0E2FF8F33A61438B1BB7D0D7D3

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xC2290

Entry point:
55, 8B, EC, 83, C4, F0, B8, D8, 1B, 41, 00, E8, 42, DA, FF, FF, 8B, 44, 24, 08, 2B, C5, 8B, 54, 24, 04, 89, 42, 04, 8B, 35, E4, 35, 46, 00, EB, 3C, 8B, 5E, 08, 8B, 7E, 0C, 03, FB, 3B, EB, 76, 02, 8B, DD, 3B, 7C, 24, 08, 76, 04, 8B, 7C, 24, 08, 3B, FB, 76, 1E, 6A, 04, 68, 00, 10, 00, 00, 2B, FB, 57, 53, E8, 26, FC, FF, FF, 85, C0, 75, 0A, 8B, 44, 24, 04, 33, D2, 89, 10, EB, 0A, 8B, 36, 81, FE, E4, 35, 46, 00, 75, BC, 83, C4, 0C, 5D, 5F, 5E, 5B, C3, 8B, C0, 53, 56, 57, 55, 51, 8B, D8, 8B, F3, 81, C6, FF, 0F...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
788 KB (806,912 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

Remove icreinstall_mp3gain.exe - Powered by Reason Core Security