legendas231.exe

Artur Kozak

The installer which is distributed via file sharing sites such as TusFiles uses the 'download manager' which wraps the original file in a adware filled bundle. The application legendas231.exe, “Installer for WinterSoft” by Artur Kozak has been detected as adware by 30 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. The setup program uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme.
Publisher:
WinterSoft  (signed by Artur Kozak)

Product:
WinterSoft

Description:
Installer for WinterSoft

Version:
2013.10.31.1157

MD5:
e2bcc3d2f1f3cda517c9574b7c6ee79b

SHA-1:
72f2fb62db10a44c7ca2dcc378d32da8cbd81c4f

SHA-256:
c055d9c1787b6fa429af6f20db5f46e046aba76f480bb2e0f60aba64737c23d5

Scanner detections:
30 / 68

Status:
Adware

Explanation:
This bunder users the InstalleRex from WebPick Internet Holdings to install add-ons such as web browser extensions, coupon plugins (WebSave) and toolbars distributed via the tusfiles.net download site.

Analysis date:
4/24/2024 9:09:55 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.10239047
943

AhnLab V3 Security
PUP/Win32.TSULoader
2014.07.07

Avira AntiVirus
ADWARE/InstallRex.Gen
7.11.158.178

avast!
Win32:InstalleRex-AH [PUP]
140617-1

AVG
Generic
2015.0.3421

Baidu Antivirus
Trojan.Win32.AntiFW
4.0.3.1476

Bitdefender
Trojan.Generic.10239047
1.0.20.935

Bkav FE
HW32.CDB
1.3.0.4959

Dr.Web
Threat.Undefined
9.0.1.05190

Emsisoft Anti-Malware
Trojan.Generic.10239047
8.14.07.06.04

ESET NOD32
Win32/InstalleRex.L potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/InstalleRex
7/6/2014

F-Secure
Trojan.Generic.10239047
11.2014-06-07_1

G Data
Trojan.Generic.10239047
14.7.24

IKARUS anti.virus
PUP.InstallRex
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.180.12626

Kaspersky
Trojan.Win32.AntiFW
15.0.0.463

Malwarebytes
PUP.Optional.InstalleRex
v2014.07.06.04

McAfee
PUP-FHQ
5600.7077

MicroWorld eScan
Trojan.Generic.10239047
15.0.0.561

NANO AntiVirus
Riskware.Win32.Downware.ctkpkg
0.28.0.60577

nProtect
Trojan.Generic.10239047
14.07.06.01

Panda Antivirus
PUP/TSUploader
14.07.06.04

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Quick Heal
Trojan.AntiFW.A5
7.14.14.00

Reason Heuristics
Adware.WebPick.Installer.L
14.8.8.0

Sophos
InstallRex
4.98

Vba32 AntiVirus
Downware.TSU
3.12.26.3

VIPRE Antivirus
Threat.4753027
29708

Zillya! Antivirus
Downloader.Adload.Win32.16886
2.0.0.1847

File size:
322.3 KB (330,080 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © 2013 WinterSoft

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\legendas231.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/21/2013 9:00:00 PM

Valid to:
8/22/2014 8:59:59 PM

Subject:
CN=Artur Kozak, O=Artur Kozak, STREET=Parkovaya 19, L=Kyiv, S=Kyiv, PostalCode=04078, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E03731FB48F020DDF5953B6498B83BC6

File PE Metadata
Compilation timestamp:
3/12/2013 5:51:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:hrIv1v16Y0JQBkQRl7174NpNUM+UHs+r65+5vpsxAZYS7eQ3eMdYnq9S4Vvy5u:hrIv1N63yRl1uqM+gs+rg+gxUYSXeMdt

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file legendas231.exe has been seen being distributed by the following 4 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to r1.getapplicationmy.info  (54.201.215.30:80)

TCP (HTTP):
Connects to c1.getapplicationmy.info  (54.201.215.30:80)

 
http://c1.getapplicationmy.info/?step_id=1&installer_id=7466233&publisher_id=445&source_id=0&page_id=0&affiliate_id=0&country_code=ES&locale=EN&browser_id=2&download_id=8066238&external_id=7496323

Remove legendas231.exe - Powered by Reason Core Security