icreinstall_openofficesetup.exe

Installer Web

Web

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The executable icreinstall_openofficesetup.exe, “Installer Web Setup ” has been detected as malware by 1 anti-virus scanner. The program is a setup application that uses the installCore installer, however the file is not signed with an authenticode signature from a trusted source. With this installer, users are expecting to download the free Apache OpenOffice but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Web

Product:
Installer Web

Description:
Installer Web Setup

MD5:
e5d89de82c257f3d62869f0ef0a17dcb

SHA-1:
4a4160e7c3efe774a23c893d8d91ccd1de39ff4e

SHA-256:
4fe16f03dc686b0fb60e5a73295f1d8b7ba9b88cdae64e36caa666541740df57

Scanner detections:
1 / 68

Status:
Malware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/16/2024 7:45:50 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic.Web.Bundler.Meta
15.7.15.14

File size:
758.7 KB (776,888 bytes)

Product version:
1.2

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_openofficesetup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:l65GpSWL3j3wqsxu7lGhiUnJhlA0abNwkdHS60pdoa+wbE2wtBExcJ1UHgAVN:l650Fjwqsxu7IhiUJ4nwkw5SaHbrwKKO

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8845

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file icreinstall_openofficesetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_openofficesetup.exe - Powered by Reason Core Security