jzipsetup-r231-n-bi.exe

jZip

Bandoo Media, Inc.

The application jzipsetup-r231-n-bi.exe by Bandoo Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from download.cdn.archivefast.com.
Publisher:
Bandoo Media Inc  (signed by Bandoo Media, Inc.)

Product:
jZip

Description:
jZip Install

Version:
2.0.0.135670

MD5:
b89fc797443bfcf2eecbc847690a1d98

SHA-1:
90de1020fec2ba455c1c7f3a898cbc673023d776

SHA-256:
09ab8e0817184d87bad409957638847c57ea96dda3d7c9766fc71df87c4c96b4

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional software offers in the setup installer included a branded Ask.com Toolbar (Movies/Music Toolbar).

Analysis date:
5/28/2024 8:48:48 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bandoo.BandooMe.Installer (M)
16.3.21.18

File size:
1.4 MB (1,417,568 bytes)

Product version:
2.0.0.135670

Copyright:
Copyright (c) 2015 Bandoo Media Inc

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\jzipsetup-r231-n-bi.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
9/17/2015 7:00:00 AM

Valid to:
2/24/2016 6:59:59 AM

Subject:
CN="Bandoo Media, Inc.", O="Bandoo Media, Inc.", L=Panama City, S=Panama, C=PA

Issuer:
CN=thawte SHA256 Code Signing CA - G2, O="thawte, Inc.", C=US

Serial number:
0AEA776A90BF58BA2DEB5770F39F9A26

File PE Metadata
Compilation timestamp:
2/25/2012 2:20:04 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:tOKqnV3CutER7v4HvAvc+YJJIMZqHorkMBXDf7cGERFeP12mGA:K3C/WYyKMZOwXDfYGqFUG

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Entropy:
7.9636

Packer / compiler:
Nullsoft install system v2.x

Code size:
29 KB (29,696 bytes)

The file jzipsetup-r231-n-bi.exe has been seen being distributed by the following URL.

Remove jzipsetup-r231-n-bi.exe - Powered by Reason Core Security