jdownloadersetup.exe

AppWork GmbH

The application jdownloadersetup.exe by AppWork GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
AppWork GmbH  (signed and verified)

MD5:
08262a08940a34068acab0edf96d5464

SHA-1:
2a0efe70fe9233f30a2b388a688942d98c911c23

SHA-256:
7701e35cfd9e10fc5d81900921f81735a11e3b9769212bfe465bbfb78e952d7b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/24/2024 9:10:48 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.Installer (M)
16.1.31.18

File size:
1.1 MB (1,113,728 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\jdownloadersetup.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
3/1/2011 8:00:48 AM

Valid to:
3/1/2014 8:00:41 AM

Subject:
E=e-mail@appwork.org, CN=AppWork GmbH, O=AppWork GmbH, L=Fürth, S=Bavaria, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012E71E7355C

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Cs2qwmNo6OYW9kbMrgls71xRIrXHFZyFh9V:R2xmm6OYWeMrgS7GvyF3

Entry address:
0xCD200

Entry point:
55, 8B, EC, 83, C4, F0, B8, 74, 35, 40, 00, E8, EA, FA, FF, FF, CC, F1, 46, 00, 8B, C0, FF, 25, 88, F1, 46, 00, 8B, C0, FF, 25, C8, F1, 46, 00, 8B, C0, FF, 25, 84, F1, 46, 00, 8B, C0, FF, 25, 80, F1, 46, 00, 8B, C0, FF, 25, 7C, F1, 46, 00, 8B, C0, FF, 25, 78, F1, 46, 00, 8B, C0, FF, 25, 74, F1, 46, 00, 8B, C0, FF, 25, 70, F1, 46, 00, 8B, C0, FF, 25, 6C, F1, 46, 00, 8B, C0, FF, 25, 68, F1, 46, 00, 8B, C0, FF, 25, 64, F1, 46, 00, 8B, C0, FF, 25, 60, F1, 46, 00, 8B, C0, FF, 25, 5C, F1, 46, 00, 8B, C0, FF, 25...
 
[+]

Entropy:
6.9514

Developed / compiled with:
Microsoft Visual C++

Code size:
837.5 KB (857,600 bytes)

Remove jdownloadersetup.exe - Powered by Reason Core Security