installer_driver_epson_stylus_office_tx300f.exe

Sagatebac

Beta Platform (Alpha Criteria Ltd.)

The application installer_driver_epson_stylus_office_tx300f.exe, “Sagatebac Setup ” by Beta Platform (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.sendchucklebulk.com.
Publisher:
Beta Platform (Alpha Criteria Ltd.)  (signed and verified)

Product:
Sagatebac

Description:
Sagatebac Setup

Version:
1.7.5.8

MD5:
00c798a12442774af686c80643db24db

SHA-1:
f7966637f86ca275f158acc466732d67ab72dcbb

SHA-256:
8d3b49b7114c23740feca6f13f3db436096924b06024ffc019ff1e5dc730490a

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
5/16/2024 4:19:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
17.3.16.6

File size:
931.9 KB (954,232 bytes)

Product version:
1.8

Copyright:
Application installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\installer_driver_epson_stylus_office_tx300f.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 5:06:52 AM

Valid to:
7/27/2016 10:11:01 AM

Subject:
CN=Beta Platform (Alpha Criteria Ltd.), O=Beta Platform (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121C0582DA1F6650EA43C09C2584F1DCEEF

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file installer_driver_epson_stylus_office_tx300f.exe has been seen being distributed by the following URL.

http://www.sendchucklebulk.com/zVky6BN3rBahIHfWpHSv9A49V5MSIVS7uITE3VDCVNdayQQ qs fnchTmw20ExDtayz75eHrDgaW1L xn3St9IA xmWopfg4HM_kds7NTEfnZbdJXV2gxoiv6KwxDq8tjutUVY6gWwPqgwreiNbhEkJx2H4NundcuVXI5DDz3QeXjOVSNBydl9_MlUfOhqSdYdgEouKnymiqS qwrlvfbmneR36V9Q==-G7ECAOSY2_82HZvFCa8n40ckAvoSjJy45j3w05O9Y3RSLaqAdz6DtLnP1E4F582SVnvr9ivI2fjJeDruTNPK0snLkxsMIn1Ctrae4svlSXkW_b d7M1fxnpXboJ54LLQnS_cYEbJG8WHJ0E30R1x9cvN0931Xfx48Zo8PiVPxNa7QpvNYt6REPRNHPAUUD8pG2uuu57a6dg1O_mFH2D2 R19PyWoDFvTX8UIaf6P P4nV4wFi3zOJc8Y1SGlNMzFXPshz3WGmthuQ1RHAMWd7iontMadlqh7R9qTcCkteFGMWTc6WPRfA6YHPQHGjTopBpQbPQDGk3A8t1LAWG9wvrVNa8RJc3Fm735Ai3f18c POwBj__b4xRelUHKtfaNRwpo2fgDVs7U4BE0smDaiPaG0HYscaErv 78nKcwfhgvf1aMGylMmAoz7SGa4YLhgkBhCoDwbHgDjcWxSBQUqZZsBxuNz6WiN0UPP6Bvu2nwOGCc_RhNGDiesqJ1YibEA