itunessetup-11136125-none.exe

Trusted Software ApS

The application itunessetup-11136125-none.exe by Trusted Software ApS has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the BundleInstaller installer. The installer is marketed through download protals and search ads as Apple's iTunes but will also install additional software offers which include adware, PUPs and browser toolbars. The file has been seen being downloaded from file.org.
Publisher:
Trusted Software ApS  (signed and verified)

MD5:
ffdbc13ca02452aadcf3ba2a0cb96bf7

SHA-1:
61d8f086f4ce4474051de9965b74327b6c2f87c9

SHA-256:
734fce0b8b5824483ac7b48538620dd8bdd0ce68e0c331632e82a0025c56f69c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 9:54:50 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TrustedSoftware.Bundler (M)
16.2.3.7

File size:
620.2 KB (635,072 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
BundleInstaller (using Inno Setup)

Common path:
C:\users\{user}\downloads\itunessetup-11136125-none.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
11/11/2010 7:00:00 PM

Valid to:
11/11/2013 6:59:59 PM

Subject:
CN=Trusted Software ApS, O=Trusted Software ApS, STREET=Blomsterhaven 42, L=Holbaek, S=n/a, PostalCode=4300, C=DK

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
1DA7007608C324C640CE3FBCC9418735

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:HyMJfsGg9Qdk7jD/KCaNd7AZJNV9BCta3lvx4SqoTZRvi:HyMJfsv9CsjwH7WJ3PColvx4ho

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.8450

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file itunessetup-11136125-none.exe has been seen being distributed by the following URL.

Remove itunessetup-11136125-none.exe - Powered by Reason Core Security