jdownloader (thefredrm).exe

JDownloader

AppWork GmbH

The application jdownloader (thefredrm).exe by AppWork GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from download2091.mediafire.com and multiple other hosts. While running, it connects to the Internet address update1.jdownloader.org on port 80 using the HTTP protocol.
Publisher:
AppWork GmbH  (signed and verified)

Product:
JDownloader

Version:
0.9

MD5:
d505ba3ff79dcc94c19f1a1b6612d0de

SHA-1:
a6fd784d79ba73ab084490bc127d79650cd7863c

SHA-256:
c00d6f323c1abfdf10b752e5d189126fa181f26c97bb27f46752e4133b500d93

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/18/2024 10:50:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.Installer (M)
15.8.22.9

File size:
25.4 MB (26,669,184 bytes)

Product version:
0.9

Copyright:
AppWork GmbH

Original file name:
JDownloaderSetup_.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\jdowloader\jdownloader (thefredrm).exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
3/1/2011 11:00:48 AM

Valid to:
3/1/2014 11:00:41 AM

Subject:
E=e-mail@appwork.org, CN=AppWork GmbH, O=AppWork GmbH, L=Fürth, S=Bavaria, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012E71E7355C

File PE Metadata
Compilation timestamp:
6/21/2011 5:10:46 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
786432:NXFsCQYV4UJ26dVkwkzV73zYvpwEt0anOOUF:PQVUJ26dVkwYVrU6

Entry address:
0x11F8

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
179.5 KB (183,808 bytes)

The file jdownloader (thefredrm).exe has been seen being distributed by the following 15 URLs.

http://download2091.mediafire.com/9kuekzgoodqg/.../JDownloaderSetup.exe

http://download2235.mediafire.com/eg3dzzg79a5g/.../JDownloaderSetup.exe

http://download1714.mediafire.com/34vv7c7mi6fg/.../JDownloaderSetup.exe

http://download2226.mediafire.com/903jz6k30k8g/.../JDownloaderSetup.exe

http://download1123.mediafire.com/9eyu7xukxpeg/.../JDownloaderSetup.exe

http://download1633.mediafire.com/7g78oj7iqf5g/.../JDownloaderSetup.exe

http://download1994.mediafire.com/35ljjxt4mtpg/.../JDownloaderSetup.exe

http://download1633.mediafire.com/sr1i6qta0jwg/.../JDownloaderSetup.exe

http://download2235.mediafire.com/n3x4dhzq4l7g/.../JDownloaderSetup.exe

http://download1767.mediafire.com/9ccq7ahzw9wg/.../JDownloaderSetup.exe

http://download2204.mediafire.com/8z40tzo5s2fg/.../JDownloaderSetup.exe

http://download2204.mediafire.com/03cf7bl758ug/.../JDownloaderSetup.exe

http://download1321.mediafire.com/6f2my8xx7ssg/.../JDownloaderSetup.exe

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to update1.jdownloader.org  (178.63.91.110:80)

Remove jdownloader (thefredrm).exe - Powered by Reason Core Security