mansion-downloader.exe

The application mansion-downloader.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. While running, it connects to the Internet address mpdedicated.com on port 80 using the HTTP protocol.
MD5:
9fbb5db88ac6ed47a1615ea3cff8d66a

SHA-1:
2f4cee01fcc62ded61d9ccc3eb13051710df8047

SHA-256:
87e529e1fc8aeeb744909ece6495cb509be193453233c9e15272cd5b3413bf4a

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/16/2024 2:04:24 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod867.Trojan
1.3.0.4562

Dr.Web
Trojan.Packed.24524
9.0.1.0361

ESET NOD32
Win32/InstallCore.FQ
7.9132

Fortinet FortiGate
W32/InstallCore.FQ
12/27/2013

K7 AntiVirus
Unwanted-Program
13.174.10410

Malwarebytes
v2013.12.27.07

McAfee
Artemis!9FBB5DB88AC6
5600.7269

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.131225

Trend Micro House Call
TROJ_GEN.F47V1122
7.2.361

VIPRE Antivirus
InstallCore
24014

File size:
735 KB (752,600 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:N2yMJfsG77wjvL+kwEO5atdFIHb/nf74rxbErwcoZ13biooFJi9c2IDKzhMmKf19:QyMJfsWEjPwBgIHb/fMrdbZ13qTiS2ny

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.8298

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to mpdedicated.com  (173.192.48.97:80)

Remove mansion-downloader.exe - Powered by Reason Core Security