JDownloaderSetup_IC.exe

JDownloader

AppWork GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application JDownloaderSetup_IC.exe by AppWork GmbH has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.descargarlo.net. While running, it connects to the Internet address ns303382.ip-94-23-204.eu on port 443.
Publisher:
AppWork GmbH  (signed and verified)

Product:
JDownloader

Version:
0.9

MD5:
7599eadd6377987de7a8074d4909729f

SHA-1:
2eacda405204adf327d81ddd440cec89652171bc

SHA-256:
efb450c19f451e6e5234a58d8bb8fb03a0db84f9762f64c51f91749e00023934

Scanner detections:
2 / 68

Status:
Potentially unwanted

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 9:46:54 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Adware.Installer.AppWorkGmbH.T
2013.7.27.18

Reason Heuristics
PUP.Installer.AppWorkGmbH.T
14.7.28.0

File size:
23.9 MB (25,101,952 bytes)

Product version:
0.9

Copyright:
AppWork GmbH

Original file name:
JDownloaderSetup_IC.exe

File type:
Executable application (Win64 EXE)

Bundler/Installer:
installCore

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\jdownloadersetup_ic.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
3/1/2011 6:00:48 AM

Valid to:
3/1/2014 6:00:41 AM

Subject:
E=e-mail@appwork.org, CN=AppWork GmbH, O=AppWork GmbH, L=Fürth, S=Bavaria, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012E71E7355C

File PE Metadata
Compilation timestamp:
1/13/2012 2:16:35 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
393216:nxMrkiIGMqq+KNaCctkC52J89j5KgMCEpJNtZymOXYR3PcIanbcnS:xEkiIGxq5NZEA6jwLJ9mu/KnbaS

Entry address:
0x11F8

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9935  (probably packed)

Code size:
181 KB (185,344 bytes)

The file JDownloaderSetup_IC.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update1.jdownloader.org  (178.63.91.110:80)

TCP (HTTP SSL):
Connects to ns303382.ip-94-23-204.eu  (94.23.204.158:443)

Remove JDownloaderSetup_IC.exe - Powered by Reason Core Security