jue412f.exe

Installer

The application jue412f.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from storage.googleapis.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Product:
Installer

Description:
Installer-H

Version:
1.0.0.0

MD5:
34286d0f0216ba8b08dd3d49ad36a307

SHA-1:
8ed3fe0a5082ccb94f347811a34a7ce89a062a6f

SHA-256:
d4a6215ada0ffda6947b7df897efe5626bafb8fe62365316f0937ffa258097e1

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 3:45:58 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.Gen
3.6.1.96

avast!
MSIL:Downloader-NG [PUP]
2014.9-150324

Baidu Antivirus
Adware.MSIL.Imali
4.0.3.15324

Dr.Web
Adware.Downware.10434
9.0.1.083

ESET NOD32
MSIL/Adware.Imali (variant)
9.11367

herdProtect (fuzzy)
2015.6.29.4

IKARUS anti.virus
PUA.MSIL.Downloader
t3scan.1.8.6.0

Kaspersky
not-a-virus:AdWare.MSIL.Agent
14.0.0.2298

File size:
2.9 MB (2,996,224 bytes)

Product version:
1.0.0.0

Original file name:
FinalInstaller_dotnet4.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\jue412f.exe

File PE Metadata
Compilation timestamp:
3/24/2015 2:02:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:kZFUj6kcZwzMgmjjTySlH4eBjMxXRhCs4B:uEXc+zXmOaH4eZMxP4

Entry address:
0x2D176E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.4440

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.8 MB (2,947,072 bytes)

The file jue412f.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove jue412f.exe - Powered by Reason Core Security