installation.exe

Installation

The application installation.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.downward1227.info.
Product:
Installation

Version:
1.9.3.0

MD5:
3e0d76b652fed33017978ff6708a080b

SHA-1:
bf9b63bf7736b19e425150ab43ee5e7bb6900f48

SHA-256:
f028fa3ceaece540e4fe4bd42e8cfcec7dab14dd7bc26029631754df5cf3ddb0

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/23/2024 8:03:15 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/Softpulse.Gen
7.11.212.228

avast!
OutBrowse-GE [PUP]
150129-1

AVG
Downloader
2016.0.3185

ESET NOD32
Win32/OutBrowse.BU potentially unwanted
9.11246

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse
15.0.0.543

McAfee
Program.Adware-OutBrowse.e
16.8.708.2

Sophos
Generic PUA ED
4.98

Trend Micro House Call
Suspici.F1E099A4
7.2.58

Vba32 AntiVirus
AdWare.OutBrowse
3.12.26.3

VIPRE Antivirus
Threat.4150696
37788

File size:
1.1 MB (1,125,993 bytes)

Product version:
1.9.3.0

Copyright:
Installation

Original file name:
Ionic.Zip-2015Feb25-030834-e2b6d7c8-3c77-47f8-8e02-8e695aa2cef0.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\installation.exe

File PE Metadata
Compilation timestamp:
2/24/2015 10:08:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:MbSaE4mvt/Ql3wCHj75/LDwI7mskwnsieho:MbSv4mvqlgQjNHwimsd6ho

Entry address:
0x7604E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5934

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464.5 KB (475,648 bytes)

The file installation.exe has been seen being distributed by the following URL.

Remove installation.exe - Powered by Reason Core Security