icreinstall_valentines-kissing.exe

Play Turtle, LLC

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_valentines-kissing.exe by Play Turtle has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Play Turtle, LLC  (signed and verified)

MD5:
c916b7f058649a015432adb94f796a2a

SHA-1:
d7cdbbc8d419a659981691818cd911a348ea20a5

SHA-256:
5e4341bec8f998de17f860829408280600a3a6bedc08032f839fa8662f18e224

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 2:39:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.EpicPlay.PlayTurtle.Bundler (M)
15.11.25.8

File size:
533.6 KB (546,432 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_valentines-kissing.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/9/2011 6:00:00 PM

Valid to:
12/9/2012 5:59:59 PM

Subject:
CN="Play Turtle, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Play Turtle, LLC", L=Plantation, S=Florida, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1FBA05C4A16403C30CAF42A3523B1862

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:1MQCIn8z0aZKVNtSUnI+152EsGEuQKaY2:UZKVHSUjiGRQKaF

Entry address:
0x10B030

Entry point:
60, BE, 00, 10, 49, 00, 8D, BE, 00, 00, F7, FF, C7, 87, 10, B7, 0C, 00, B8, BA, AB, 6E, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8504

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
492 KB (503,808 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

Remove icreinstall_valentines-kissing.exe - Powered by Reason Core Security