itunes10.exe

Installer

OpenInstall, Inc.

The application itunes10.exe by OpenInstall has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from dl02.s3.amazonaws.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
OpenInstall   (signed by OpenInstall, Inc.)

Product:
Installer

Version:
1,18,0,1514

MD5:
c638d3dfefbd24c43ebfa8eb326391c3

SHA-1:
b1f73b150e87ce93328372ffeb1e296fe985f7c8

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Includes Open Install, an installer which bundles legitimate programs with offers for additional 3rd-party applications that may be unwanted by the user.

Analysis date:
4/25/2024 8:41:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OpenInstall.Installer (M)
16.1.26.17

File size:
236.1 KB (241,744 bytes)

Product version:
1,18,0,1514

Copyright:
Copyright © 2010

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\itunes10.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/20/2011 6:00:00 PM

Valid to:
1/24/2013 6:00:00 AM

Subject:
CN="OpenInstall, Inc.", O="OpenInstall, Inc.", L=San Francisco, S=California, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07AE9941492080181D2477353500DE05

File PE Metadata
Compilation timestamp:
11/29/2011 11:21:21 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:QL/4gIi0FcKgY4QXlksfDQ93ha4l0uYnjXzLxnRLsD:QTWcKh1XlksERha97xRoD

Entry address:
0x82540

Entry point:
60, BE, 00, F0, 44, 00, 8D, BE, 00, 20, FB, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.7447

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
208 KB (212,992 bytes)

The file itunes10.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove itunes10.exe - Powered by Reason Core Security