InstantSupport.exe

InstantSupport

Installer Technology Co.

The executable InstantSupport.exe, “InstantSupport Tray Window” has been detected as malware by 1 anti-virus scanner. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘InstantSupport’. While running, it connects to the Internet address 172-245-127-102-host.colocrossing.com on port 80 using the HTTP protocol.
Publisher:
Installer Technology  (signed by Installer Technology Co.)

Product:
InstantSupport

Description:
InstantSupport Tray Window

Version:
1.0.29.7

MD5:
9e9834f25cf414197faebe096578e135

SHA-1:
464d5e13bdd9a516cfc25fb7e55ea1daa388795e

SHA-256:
ca6aacf7e55e3f3d5b87235b5f7ae269718f470fece756583dfcb8c8c382df0e

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
4/26/2024 6:27:33 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.16.5

File size:
6.2 MB (6,550,672 bytes)

Product version:
1.0.29.7

Copyright:
Copyright Installer Technology 2015

Original file name:
InstantSupport.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\instantsupport\instantsupport.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/27/2016 5:00:00 PM

Valid to:
9/28/2017 4:59:59 PM

Subject:
CN=Installer Technology Co., O=Installer Technology Co., STREET=407 lincoln road, L=miami beach, S=florida, PostalCode=33139, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1B58BBA81BB22C023967D6D579B294FC

File PE Metadata
Compilation timestamp:
2/15/2017 5:24:04 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x13F709

Entry point:
E8, B3, 8E, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, C0, CF, 5C, 00, 75, 02, F3, C3, E9, 87, 23, 00, 00, 51, C7, 01, C0, 6B, 59, 00, E8, 4E, 94, 00, 00, 59, C3, 55, 8B, EC, 8D, 41, 09, 50, 8B, 45, 08, 83, C0, 09, 50, E8, AD, 93, 00, 00, F7, D8, 59, 1B, C0, 59, 40, 5D, C2, 04, 00, 55, 8B, EC, 56, 8B, F1, E8, C9, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 70, FA, ED, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, FF, 75, 18, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 05, 00, 00, 00, 83, C4, 18...
 
[+]

Entropy:
6.1969

Code size:
1.4 MB (1,486,336 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
InstantSupport

Command:
"C:\Program Files\instantsupport\instantsupport.exe" -startup


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 172-245-127-102-host.colocrossing.com  (172.245.127.102:80)

TCP (HTTP):
Connects to 172-245-127-171-host.colocrossing.com  (172.245.127.171:80)

TCP (HTTP):
Connects to 74-115-2-240.anchorfree.com  (74.115.2.240:80)

TCP (HTTP):
Connects to 74-115-0-148.anchorfree.com  (74.115.0.148:80)

Remove InstantSupport.exe - Powered by Reason Core Security