jZipSetup-r100-w-bc.exe

jZip

Bandoo Media Inc

The application jZipSetup-r100-w-bc.exe by Bandoo Media Inc has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from download.cdn.jzip.com and multiple other hosts. While running, it connects to the Internet address https-178-79-238-128.mrs.llnw.net on port 80 using the HTTP protocol.
Publisher:
Bandoo Media Inc  (signed and verified)

Product:
jZip

Description:
jZip Install

Version:
2.0.0.134244

MD5:
038d72d4e54b2dd469050f96ff75a3ce

SHA-1:
b017681fceb58717231affb3fb905aef8691a6b8

SHA-256:
473476dc9af24ede2346cf6d523c92fc701ad5d9b5b80676b87ee0718bf3dff2

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional software offers in the setup installer included a branded Ask.com Toolbar (Movies/Music Toolbar).

Analysis date:
4/23/2024 2:51:42 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Bandoo.13
9.0.1.0345

Malwarebytes
PUP.Optional.Bandoo.A
v2013.12.11.10

Reason Heuristics
PUP.Optional.Installer.BandooMedia.T
14.3.1.4

File size:
1.2 MB (1,297,728 bytes)

Product version:
2.0.0.134244

Copyright:
Copyright (C) 2013 Bandoo Media Inc

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\jzipsetup-r100-w-bc.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/18/2012 8:00:00 PM

Valid to:
10/5/2014 7:59:59 PM

Subject:
CN=Bandoo Media Inc, O=Bandoo Media Inc, L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
32B24D9C6170CB3DA53A710307649B95

File PE Metadata
Compilation timestamp:
5/30/2013 4:09:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:cGK/PYYviuzoIQvC7rJX9hR9EdNhYDQQg3IR85X3dQkMBPUar:kYYyvCvJnXKTYDQQgYRaqlPr

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, BC, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 25, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 80, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 8F, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 7D, 27, 00, 00...
 
[+]

Entropy:
7.9569

Packer / compiler:
Nullsoft install system v2.x

Code size:
29.5 KB (30,208 bytes)

The file jZipSetup-r100-w-bc.exe has been seen being distributed by the following 29 URLs.

http://download.cdn.jzip.com/cdn/r/.../jZipSetup-r131-n-bi.exe

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to https-178-79-238-128.mrs.llnw.net  (178.79.238.128:80)

Remove jZipSetup-r100-w-bc.exe - Powered by Reason Core Security