internet download manager 5.exe

Web application

MaxPlatform (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application internet download manager 5.exe, “Web application Setup ” by MaxPlatform (Fried Cookie) has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Software   (signed by MaxPlatform (Fried Cookie Ltd))

Product:
Web application

Description:
Web application Setup

Version:
5.8.4.3

MD5:
7d2c368c412e0093c5ac04eb47c6d50c

SHA-1:
50c69dae7920214d84ea33bed34cbe9241f3dd64

SHA-256:
d0256ee1c19fccdf987f1d2c323b6ca3bae68aa71ec6b311dc5969a95841536b

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 2:12:48 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

AVG
Generic
2016.0.2943

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.151028

Bkav FE
W32.HfsAdware
1.3.0.7383

Dr.Web
Trojan.InstallCore.864
9.0.1.0301

ESET NOD32
Win32/InstallCore.ACZ potentially unwanted (variant)
9.12473

Fortinet FortiGate
Riskware/InstallCore
10/28/2015

K7 AntiVirus
Adware
13.212.17669

Malwarebytes
v2015.10.28.01

McAfee
Artemis!7D2C368C412E
5600.6599

Panda Antivirus
PUP/Multitoolbar
15.10.28.01

Reason Heuristics
PUP.InstallCore.Installer.Installer (M)
15.10.28.1

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.151026

Sophos
Install Core Click run software (PUA)
4.98

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
3.12.26.4

VIPRE Antivirus
InstallCore
44850

Zillya! Antivirus
Trojan.Bladabindi.Win32.58383
2.0.0.2478

File size:
1005.9 KB (1,030,008 bytes)

Product version:
3.0

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/27/2015 9:42:25 AM

Valid to:
4/27/2016 9:42:25 AM

Subject:
CN=MaxPlatform (Fried Cookie Ltd), O=MaxPlatform (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121507E6BDD0438A3C158F873DCAA10634D

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:5szVfMuKQnrmqrjW4rnnahx0DRmPUQ5lbJUcSuiJp+f:5cRMZyrTbO6pQpUJuiJAf

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9298

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file internet download manager 5.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to mirror2.internetdownloadmanager.com  (50.97.82.44:80)

TCP (HTTP):
Connects to ec2-54-247-183-102.eu-west-1.compute.amazonaws.com  (54.247.183.102:80)

TCP (HTTP):
Connects to ec2-54-194-79-57.eu-west-1.compute.amazonaws.com  (54.194.79.57:80)

TCP (HTTP):
Connects to ec2-23-23-107-202.compute-1.amazonaws.com  (23.23.107.202:80)

TCP (HTTP):
Connects to 92b91b35.rdns.100tb.com  (146.185.27.53:80)

TCP (HTTP):
Connects to 92b91b2d.rdns.100tb.com  (146.185.27.45:80)

TCP (HTTP):
Connects to 50.115.122.45.static.westdc.net  (50.115.122.45:80)

Remove internet download manager 5.exe - Powered by Reason Core Security