installer_winrar.exe

Sagatebac

Beta Platform (Alpha Criteria Ltd.)

The application installer_winrar.exe, “Sagatebac Setup ” by Beta Platform (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. With this installer, users are expecting to download WinRAR archiver but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Beta Platform (Alpha Criteria Ltd.)  (signed and verified)

Product:
Sagatebac

Description:
Sagatebac Setup

Version:
1.7.5.8

MD5:
4c0d063fed1328c7760c4f941b5394f1

SHA-1:
87265be16b017a9c9f0528ccba745b64ac339ead

SHA-256:
2b2141be521f772f9770a9cbc659710c2dcc9bbaa06d5767f627a3307cbc8091

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/16/2024 4:06:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
17.3.16.10

File size:
931.9 KB (954,232 bytes)

Product version:
1.8

Copyright:
Application installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\installer_winrar.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 11:06:52 AM

Valid to:
7/27/2016 5:11:01 PM

Subject:
CN=Beta Platform (Alpha Criteria Ltd.), O=Beta Platform (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121C0582DA1F6650EA43C09C2584F1DCEEF

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file installer_winrar.exe has been seen being distributed by the following URL.

http://www.sendchucklebulk.com/slwJ05ICri0WJOQO1XkakMslysJnvK8Iq1vu46kvpe58_YoDMyxUq0NhH BxGPM0jtUGoZFI03ynxhecFC1dUVFV1cSQkzy0MNDhbKlz89uQSsCbJYYVvRnnWjf4q3qenXpc6VR78_z7lr eLMG0sLwCThBW0uaJKK65Z3xCvVYouTD4sVbtTyRQZR6Kl5SYFwMXg0W_4umpa0IHw_uZkZ6P5cnH9vIVeen_Pk 938WQRylh4_UG4 dutTTpGzdVS3NEaZrzwvqFjsfl3ZEQehnP2pwPYSFMyK0D 8vbT3f QXZEfJm4TBZkTNrFixoUDcjkJEsa_vuCYUyX4jtqC7 WPYV3nbelDLMhQk5vwT613Bf_k_Zk3L6PU7 eXZE7i3UD7tqP Kh3R975 NeBgVzbDFLk eTYcmkPabrsZzxN6qPvy4PZYM9H8p_lNXB88wj2GFX8 CPL45KrobZfCH1mpxZ14tJR28oooQvzDZddnZtFNo1bh_bHV7Xco5oRlHsGBpQeATE y5SYwrK4c_PbRisOylacP7iueG3_PYL9wjm9oPM0uCy1uRa8WoE_TACY2lS8x9Cl9M3t6uP08YoOVOuvZGA9bZMe9231Tq7zV8CCBLPP HL2b5KevgwKLwkulyQCL52xLFm M1R7KwJIbHmhRSo85RMOFwcErRX4vFlS0asRMbWhboKHv9kSFBB8jCES AYXnvFD7h1jKu_KuRhepjgRCeOiZGGVNW18hTxZ5qfVaQce0C Bytnph2t8ETSzZ5RwDx_KRh3dY1sllUseKNNe5K8eEyLIyyDsFpwThD21g1CPAJu4Q_scssJITMeqQWmWvGXB8xnRk6Mg0qMThTi9mX4ZkUiQRv3LZr6Ben7ExEwkVA 9Ny39cv8VFFVLcmuF4kHICAAIeVnrbfOg5ebm prUtiMGTyKWgpp6iJlOm0ZIiDHdGZz8Utl_sfX1

Remove installer_winrar.exe - Powered by Reason Core Security