installer_tweeter_bot_english.exe

Descarga Segura LLC

The application installer_tweeter_bot_english.exe by Descarga Segura has been detected as a potentially unwanted program by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The file has been seen being downloaded from download.downplex.smsstatus.com.
Publisher:
Descarga Segura LLC  (signed and verified)

MD5:
a0ff41f3d0f2f4fcd103de81da3ea5d9

SHA-1:
7dc81cca61d917ae09c106cba8131c8053b4b661

SHA-256:
d9dcb9767fbe6468c0e9f5d6eb6f6d7846ab283268fab10f776a83cf60fa7a04

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Analysis date:
4/18/2024 6:48:09 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/Descarga.A
7.11.172.2

avast!
Toolbar-O [Adw]
140908-2

AVG
Skodna.Bundle.d71
2015.0.3351

Comodo Security
ApplicUnwnt.Win32.Lollipop.C
19516

Dr.Web
Adware.Downware.1058
9.0.1.05190

ESET NOD32
Win32/Toolbar.Babylon potentially unwanted application
7.0.302.0

K7 AntiVirus
Adware
13.183.13358

Malwarebytes
PUP.BundleInstaller.DES
v2014.09.15.04

NANO AntiVirus
Trojan.Win32.Downware.yrejy
0.28.2.61942

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
PUP.DescargaSegura.DD
14.9.14.22

Sophos
Descarga Segura
4.98

SUPERAntiSpyware
Adware.Lollipop/Variant
10359

VIPRE Antivirus
Threat.4782551
33120

File size:
247.8 KB (253,712 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\installer_tweeter_bot_english.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
4/16/2012 10:10:02 AM

Valid to:
3/30/2013 11:26:34 AM

Subject:
CN=Descarga Segura LLC, O=Descarga Segura LLC, L=Wilmington, S=DE, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B7BB975505926

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:HgXdZt9P6D3XJP4BFffE3rCxJkOdDTr+LJfgkPTvuoZ124KL10v1vBFcs2ENFQRP:He340ffE3rCxCLlBZ0l1QHcs2xiQX

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.7165

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_tweeter_bot_english.exe has been seen being distributed by the following URL.

Remove installer_tweeter_bot_english.exe - Powered by Reason Core Security