install_jd_one.exe

Appwork GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application install_jd_one.exe by Appwork GmbH has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from pf.dlcvit.com and multiple other hosts. While running, it connects to the Internet address installer.jdownloader.org on port 80 using the HTTP protocol.
Publisher:
Appwork GmbH  (signed and verified)

MD5:
98c3d62f8de477f381c86604b0df57fe

SHA-1:
fd52681d84ded9358ca7b059f898dd2377bdaa6c

SHA-256:
68782654b05f38c7f1bce085a3fadc96b1d41eb1aab780357941306a87a2aaf1

Scanner detections:
2 / 68

Status:
Potentially unwanted

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/18/2024 5:15:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AppworkGmbH
15.1.24.22

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

File size:
226.1 KB (231,544 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Nullsoft Install System)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/15/2014 10:00:00 AM

Valid to:
8/16/2015 9:59:59 AM

Subject:
CN=Appwork GmbH, O=Appwork GmbH, L=Fürth, S=Bayern, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0091626FD168636EDD78A174E8B75DAC

File PE Metadata
Compilation timestamp:
5/12/2014 6:03:42 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:l4SUjht47NcyrGrDFmd5poaXme0mp5B6Ay3X53gx5C/Yi:+TEd5po9BmD4Ay32xA/D

Entry address:
0x30E2

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 58, E4, 42, 00, E8, 95, 2D, 00, 00, A3, A4, E3, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, E0, 87, 42, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, A0, DB, 42, 00, E8, 3F, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 40, 43, 00, 50, 55, E8, 2D, 2A...
 
[+]

Entropy:
7.3737

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file install_jd_one.exe has been seen being distributed by the following 13 URLs.

http://pf.dlcvit.com/s/8/.../80176-670969-jdownloader.exe

http://fetch.jdcdn.org/4749210201022171010.php?l=4&t=1430777660&v=1&e=1430777665&s=r9hjd2EnzPsxRn1KgCTCfqLLk20

http://fetch.jdcdn.org/699045926859194895.php?l=4&t=1429818873&v=1&e=1429818878&s=2rEDoLsxyQI0mnYdxH8qIjoZWfA

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to installer.jdownloader.org  (85.131.130.148:80)

Remove install_jd_one.exe - Powered by Reason Core Security