installer_openoffice.exe

Inffinity Internet

The application installer_openoffice.exe by Inffinity Internet has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from download.phpnuke.org.
Publisher:
Inffinity Internet  (signed and verified)

MD5:
059a247828f15c7101cff1bc02a745d2

SHA-1:
e52c888e0ca1a5f3a98a774f497c8be427eef62c

SHA-256:
6e42d94cf54db60d2d362cbf5a2000997b50247fdbd02034b8751d8f9d68720d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 6:22:43 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Inffinity (M)
16.7.24.15

File size:
492.8 KB (504,600 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\installer_openoffice.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/18/2012 2:00:00 AM

Valid to:
1/18/2013 1:59:59 AM

Subject:
CN=Inffinity Internet, OU=Internet, O=Inffinity Internet, L=Madrid, S=Madrid, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1E478AE33382A025ECAE98EF6ADEE5BB

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:3e34R2ZP54Z7zh36dqXEV2rnCAZG/t7FTBqTzP7n7O7L6K2Bfo7pJ:j2A1zh36VV2GW0ZTsnz7O7L6ju7pJ

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
6.0988

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_openoffice.exe has been seen being distributed by the following URL.

Remove installer_openoffice.exe - Powered by Reason Core Security