infigo_setup_ic.exe

Internet software

MAVIN LOG, S.L.

The application infigo_setup_ic.exe, “Internet software Setup ” by MAVIN LOG, S.L has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.infigo-cleaner.com.
Publisher:
Web Application   (signed by MAVIN LOG, S.L.)

Product:
Internet software

Description:
Internet software Setup

Version:
5.7.3.6

MD5:
d507d8203a96e79ee2b10c315e92a5a3

SHA-1:
ad5e4f8b75619aa124e022913bf0969c60d2c0e0

SHA-256:
4e8fab53f085b0b672ee01ab4a33929a4e98335852bfe1482c1aa0d890416db5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 7:33:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.RES (M)
16.8.10.19

File size:
832 KB (852,000 bytes)

Product version:
1.3.0

Copyright:
Installer

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\infigo_setup_ic.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/3/2014 2:00:00 AM

Valid to:
11/2/2016 12:59:59 AM

Subject:
CN="MAVIN LOG, S.L.", O="MAVIN LOG, S.L.", L=Las Palmas de Gran Canaria, S=Las Palmas, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2A7C2F47EC1B4B9270591EE153868BBB

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:wdcVUZkKBXLwv9afcNsMjnoHKRZYPNWwUg+1W65UHQ+h:wyrKBXc9wcNcKRZLJWUUP

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file infigo_setup_ic.exe has been seen being distributed by the following URL.

Remove infigo_setup_ic.exe - Powered by Reason Core Security