law-enforcer.exe

The application law-enforcer.exe has been detected as a potentially unwanted program by 28 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from installerlaunch-mtfg1.com.
MD5:
b650a2a712f13213819e1a98096c3c34

SHA-1:
4a7207a2e1a2358616158803ba54e1d1a33985de

SHA-256:
37b4257ffe11db7d64517eb72dc002aa627a898213629bb69a860b3f4b296a2a

Scanner detections:
28 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/27/2024 12:17:13 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.62453
684

Agnitum Outpost
Trojan.Adware
7.1.1

AhnLab V3 Security
PUP/Win32.InstallCore
15.03.23

Avira AntiVirus
ADWARE/Adware.Gen
7.11.30.172

Bitdefender
Gen:Variant.Adware.Graftor.62453
1.0.20.410

Bkav FE
W32.HfsAutoA
1.3.0.4959

Clam AntiVirus
W32.Adware.InstallCore
0.98/213

Dr.Web
Adware.InstallCore.40
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.62453
8.15.03.23.09

ESET NOD32
Win32/InstallCore.Q potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.C.gen
v6.4.6.5.141

F-Secure
Gen:Variant.Adware.Graftor.62453
11.2015-23-03_2

G Data
Gen:Variant.Adware.Graftor.62453
15.3.24

herdProtect (fuzzy)
2015.6.28.8

IKARUS anti.virus
AdWare.SuspectCRC
t3scan.1.6.1.0

K7 AntiVirus
Riskware
13.177.12109

MicroWorld eScan
Gen:Variant.Adware.Graftor.62453
16.0.0.246

NANO AntiVirus
Trojan.Win32.InstallCore.bclgws
0.28.0.59911

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.InstallCore!6.DCE
23.00.65.15321

Sophos
Install Core Installer
4.98

SUPERAntiSpyware
Adware.InstallCore
9980

Total Defense
Win32/InstallCore!Adware
37.0.10942

Trend Micro House Call
HT_INSTALLCORE_BK0802C9.TOMC
7.2.82

Trend Micro
HT_INSTALLCORE_BK0802C9.TOMC
10.465.23

Vba32 AntiVirus
Adware.InstallCore.gen
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
29302

Zillya! Antivirus
Trojan.Genome.Win32.201656
2.0.0.1800

File size:
1 MB (1,070,720 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\law-enforcer.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:zPqxmfxN1ixtiZy6MntoNXfRya9YST1oUrp3v:zqxUH4iZN80PsbST1D

Entry address:
0xC1A73

Entry point:
55, 8B, EC, 83, C4, F0, B8, 63, D8, 49, 00, E8, 85, E7, FF, FF, 6C, 79, F0, 98, FD, C3, 73, 83, FE, B7, 61, A5, 3F, B5, 05, 1B, 6F, 83, 89, 29, 89, 04, 1B, E5, 20, 68, 28, DD, 74, 60, EF, E4, 8F, 40, 8D, 9C, BF, 24, 20, 5E, 2B, 71, D3, 90, 5C, 5C, D2, 9B, 00, 3D, 74, FB, 37, DF, 2F, 34, 2D, 21, 1E, 8B, DD, 75, 20, E9, 33, 43, E5, 37, EF, 0E, 6D, 11, 0A, F5, C5, B8, 61, 07, 1D, 90, 0B, 45, 67, 8D, 89, 8A, 2B, 6A, AC, 96, 41, 8B, 05, EC, 8E, D8, 09, 56, 08, 02, 6A, 2B, 8E, F5, 39, BA, 68, 71, C7, 71, 6A, FD...
 
[+]

Entropy:
6.7124

Developed / compiled with:
Microsoft Visual C++

Code size:
786.5 KB (805,376 bytes)

The file law-enforcer.exe has been seen being distributed by the following URL.

Remove law-enforcer.exe - Powered by Reason Core Security