installer_avg_anti-virus_free_edition_english.exe

The application installer_avg_anti-virus_free_edition_english.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from 3b6ffd18.cdn.programvaradwn.com and multiple other hosts.
MD5:
2deea9bbd5a56d1581fd90841301ed9b

SHA-1:
6f33c4eb08f536effb58d6cebf17b5ed35f65465

SHA-256:
ffc1c67e2471d3e8ba5b6dc7d68b60f20d381180777617a144570c9a513b7729

Scanner detections:
19 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/11/2024 1:57:55 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.188.150

Bkav FE
W32.Clode27.Trojan
1.3.0.4959

Comodo Security
Application.Win32.InstallCore.FJ
20187

Dr.Web
Trojan.Packed.28474
9.0.1.05190

ESET NOD32
Win32/InstallCore.BY potentially unwanted application
7.0.302.0

F-Prot
W32/A-42c63c6c
v6.4.7.1.166

G Data
Win32.Application.InstallCore
14.12.24

K7 AntiVirus
Unwanted-Program
13.185.14120

Malwarebytes
v2014.12.23.11

McAfee
Artemis!8BFD0B0BE4AB
5600.6908

NANO AntiVirus
Riskware.Win32.InstallCore.dimzdi
0.28.6.63726

Panda Antivirus
PUP/MultiToolbar.A
14.12.23.11

Qihoo 360 Security
Win32/Virus.Adware.0b0
1.0.0.1015

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141221

Sophos
PUA 'Install Core Click run software'
5.09

SUPERAntiSpyware
10160

Trend Micro House Call
TROJ_GEN.R047C0OKB14
7.2.357

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
InstallCore
35108

File size:
727 KB (744,448 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\installer_avg_anti-virus_free_edition_english.exe

File PE Metadata
Compilation timestamp:
6/20/1992 10:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:CyMJfsGj/0nDVICvQBdUtY2YAJH1gU0zlTdkXc2Uesl7VPdB7bcCRwkKhCs+xcg:CyMJfsU/8QsfT+xhdk6HtB7AENcg

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.8157

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file installer_avg_anti-virus_free_edition_english.exe has been seen being distributed by the following 2 URLs.