installer.exe

Antanda, LLC

The application installer.exe by Antanda has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address 74-208-236-71.elastic-ssl.ui-r.com on port 80 using the HTTP protocol.
Publisher:
Antanda, LLC  (signed and verified)

Version:
1.0.0.1

MD5:
ce589098b9d793e5a8433d9f31fa027d

SHA-1:
e8722a010cc9b31c327ae3b1abb44003017a9ed8

SHA-256:
2798ec77f3929f12bc4fe548fd276edd0e2932c0bb2bcb1ac2a33f31749b822c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 11:29:32 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Antanda.Installer (M)
16.3.21.16

File size:
395.8 KB (405,280 bytes)

Product version:
1.0.0.1

Copyright:
All rights reserved.

Original file name:
DownloadAll_v2.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\installer.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
8/13/2011 3:30:41 PM

Valid to:
8/11/2012 9:05:47 PM

Subject:
CN="Antanda, LLC", O="Antanda, LLC", L=Irvine, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
27A44FC53266B3

File PE Metadata
Compilation timestamp:
8/16/2011 2:44:44 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:KmtbifwfkKRsQLx1Eny2jznm9+B9AHKyjVrTLkkP7qcXvxZzchEEKLS:KofkKRPnEny2jzo5j1QkjqcpW0O

Entry address:
0xC341

Entry point:
E8, E1, 6B, 00, 00, E9, 79, FE, FF, FF, C3, B8, 75, 3A, 41, 00, A3, E4, 3D, 42, 00, C7, 05, E8, 3D, 42, 00, 5C, 31, 41, 00, C7, 05, EC, 3D, 42, 00, 10, 31, 41, 00, C7, 05, F0, 3D, 42, 00, 49, 31, 41, 00, C7, 05, F4, 3D, 42, 00, B2, 30, 41, 00, A3, F8, 3D, 42, 00, C7, 05, FC, 3D, 42, 00, ED, 39, 41, 00, C7, 05, 00, 3E, 42, 00, CE, 30, 41, 00, C7, 05, 04, 3E, 42, 00, 30, 30, 41, 00, C7, 05, 08, 3E, 42, 00, BD, 2F, 41, 00, C3, 8B, FF, 55, 8B, EC, E8, 96, FF, FF, FF, E8, 67, 77, 00, 00, 83, 7D, 08, 00, A3, 3C...
 
[+]

Code size:
109.5 KB (112,128 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 74-208-236-71.elastic-ssl.ui-r.com  (74.208.236.71:80)

Remove installer.exe - Powered by Reason Core Security