icreinstall_openoffice_packages.exe

AccuInstall

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_openoffice_packages.exe by AccuInstall has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
AccuInstall  (signed and verified)

MD5:
139deb776e15329d276a0f352d8399c7

SHA-1:
1fa9730c904a677224f1283f9c61bce2885795c6

SHA-256:
758aa56c97ed1104efb9a06594bbe5cd56b3d31594b174908bd9cb99d9592c25

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Analysis date:
4/26/2024 4:15:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.AccuInstall (M)
16.2.1.23

File size:
1 MB (1,095,352 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_openoffice_packages.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/6/2011 6:00:00 PM

Valid to:
11/6/2013 5:59:59 PM

Subject:
CN=AccuInstall, O=AccuInstall, STREET=2360 Corporate Circle, STREET=Suite 400, L=Henderson, S=NV, PostalCode=89074, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C7A24A726209072AC474B795FA0984AA

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:7fZJEpXz1qUD7ZXQj+gREIanbvqgczYFgK1NS4uL:7xJWXzfD7TgROqgc61Ne

Entry address:
0xCD5F0

Entry point:
55, 8B, EC, 83, C4, F0, B8, E0, 41, 41, 00, E8, 7B, DF, FF, FF, 6D, FF, 25, B8, 51, 47, 00, 8B, C0, FF, 25, B4, 51, 47, 00, 8B, C0, FF, 25, B0, 51, 47, 00, 8B, C0, FF, 25, AC, 51, 47, 00, 8B, C0, FF, 25, A8, 51, 47, 00, 8B, C0, FF, 25, A4, 51, 47, 00, 8B, C0, FF, 25, A0, 51, 47, 00, 8B, C0, FF, 25, 9C, 51, 47, 00, 8B, C0, FF, 25, 98, 51, 47, 00, 8B, C0, FF, 25, 94, 51, 47, 00, 8B, C0, FF, 25, 90, 51, 47, 00, 8B, C0, FF, 25, 8C, 51, 47, 00, 8B, C0, FF, 25, CC, 51, 47, 00, 8B, C0, FF, 25, 88, 51, 47, 00, 8B...
 
[+]

Entropy:
6.9419

Developed / compiled with:
Microsoft Visual C++

Code size:
837.5 KB (857,600 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

Remove icreinstall_openoffice_packages.exe - Powered by Reason Core Security