icreinstall_setup.exe

Fried Cookie Ltd

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_setup.exe by Fried Cookie has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Fried Cookie Ltd  (signed and verified)

MD5:
96fc32af67f29fc8f0768cf6371068a9

SHA-1:
4c0b60486109275533324504366be04abee4580c

SHA-256:
28bb38b8364c99eb23157819a3815c218e4d58c6375f1485d29016d49c869f45

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 6:43:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore (M)
17.3.15.21

File size:
1.3 MB (1,315,632 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_setup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/3/2012 7:00:00 AM

Valid to:
5/4/2014 6:59:59 AM

Subject:
CN=Fried Cookie Ltd, O=Fried Cookie Ltd, L=Tel Aviv, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3739B9B5702964D0DD4429F69D6595EC

File PE Metadata
Compilation timestamp:
7/3/2001 3:24:39 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x9386

Entry point:
55, 8B, EC, 6A, FF, 68, 90, A2, 40, 00, 68, 06, 95, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, E4, A0, 40, 00, 59, 83, 0D, 1C, DE, 40, 00, FF, 83, 0D, 20, DE, 40, 00, FF, FF, 15, E0, A0, 40, 00, 8B, 0D, 18, DE, 40, 00, 89, 08, FF, 15, 18, A1, 40, 00, 8B, 0D, 14, DE, 40, 00, 89, 08, A1, E8, A0, 40, 00, 8B, 00, A3, 24, DE, 40, 00, E8, 10, 01, 00, 00, 39, 1D, B0, C9, 40, 00, 75, 0C, 68, 02, 95, 40, 00, FF, 15, EC, A0...
 
[+]

Entropy:
7.0396

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
33.5 KB (34,304 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_setup.exe - Powered by Reason Core Security