İnternet_Download_Manager.exe

The application İnternet_Download_Manager.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.kurulumtr.com and multiple other hosts.
MD5:
ed393c51140689a0aec60e2d277ddb05

SHA-1:
fae40eb3ca170e32c29eb23c29910785fecb1161

SHA-256:
b79213c964c65928eaed7d0804fc66f494370f1cb6cc3bd90394202a65bb562f

Scanner detections:
20 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/23/2024 5:52:28 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Spnr
2013.12.23

Avira AntiVirus
7.11.121.92

avast!
Win32:PUP-gen [PUP]
2014.9-131224

Bkav FE
W32.Clod2ff.Trojan
1.3.0.4613

Comodo Security
Application.Win32.InstallCore.~A
17485

Dr.Web
Trojan.DownLoader10.41344
9.0.1.0358

ESET NOD32
Win32/InstallCore.FJ (variant)
7.9190

Fortinet FortiGate
W32/Hra.BT!tr
12/24/2013

G Data
Win32.Application.InstallCore
13.12.22

K7 AntiVirus
Trojan
13.174.10588

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.4574

Malwarebytes
Adware.Agent.IC
v2013.12.24.05

McAfee
RDN/Generic.hra!bt
5600.7272

Norman
Suspicious_Gen4.FFYWG
11.20131224

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.131222

Trend Micro House Call
TROJ_SPNR.08KE13
7.2.358

Trend Micro
TROJ_SPNR.08KE13
10.465.24

VIPRE Antivirus
Trojan.Win32.Generic
24656

XVirus List
Win.Detected
2.3.31

File size:
667.8 KB (683,864 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\internet_download_manager.exe

File PE Metadata
Compilation timestamp:
1/9/2012 3:44:06 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:sxaVAh64U5lu3XnwbDo4Bwd/tNzIoNY31Kwe3notXMBWRC0cQ0tROgk9Li7S:sxaVxr5EHgDHYLzbECmXMBGM17k9m7S

Entry address:
0xB3C1

Entry point:
E8, E3, FE, FF, FF, 33, C0, 50, 50, 50, 50, E8, F2, 2D, 00, 00, C3, 56, 57, 8B, 7C, 24, 0C, 8B, F1, 8B, CF, 89, 3E, E8, B0, A1, FF, FF, 89, 46, 08, 89, 56, 0C, 8B, 87, 1C, 0C, 00, 00, 89, 46, 10, 5F, 8B, C6, 5E, C2, 04, 00, 8B, C1, 8B, 08, 8B, 50, 10, 3B, 91, 1C, 0C, 00, 00, 75, 0D, 6A, 00, FF, 70, 0C, FF, 70, 08, E8, D9, A6, FF, FF, C3, 55, 8B, EC, 83, EC, 1C, 56, 33, F6, 56, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 40, 32, 41, 00, 85, C0, 74, 21, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 44, 32, 41, 00, 8D, 45, E4...
 
[+]

Entropy:
7.9226  (probably packed)

Code size:
71 KB (72,704 bytes)

The file İnternet_Download_Manager.exe has been seen being distributed by the following 3 URLs.

http://www.kurulumtr.com/GTA 3 -.exe

Remove İnternet_Download_Manager.exe - Powered by Reason Core Security