messenger-plus--live-5500761-baixaki-32-bits-18102012185644.exe

The application messenger-plus--live-5500761-baixaki-32-bits-18102012185644.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from dl.baixaki.com.br.
MD5:
34c17ed7f6b825a171adc1abfcbdfe75

SHA-1:
eb9b330202d84b27f02dd03388c3f7c36781c458

SHA-256:
56dab27245909a27a6c44ba5a2dad45e62e282ba7e329badedca6938bbc33278

Scanner detections:
21 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 8:33:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.559755
353

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
ADWARE/InstallCo.AB
8.3.1.6

Arcabit
Adware.Generic.D88A8B
1.0.0.425

AVG
InstallCore
2017.0.2831

Bitdefender
Adware.Generic.559755
1.0.20.240

Dr.Web
Adware.InstallCore.72
9.0.1.048

Emsisoft Anti-Malware
Adware.Generic.559755
8.16.02.17.07

ESET NOD32
Win32/InstallCore.AY potentially unwanted (variant)
10.11743

Fortinet FortiGate
Riskware/InstallCore
2/17/2016

F-Secure
Adware.Generic.559755
11.2016-17-02_4

G Data
Adware.Generic.559755
16.2.25

K7 AntiVirus
Trojan
13.204.16151

Malwarebytes
PUP.AdBundle
v2016.02.17.07

MicroWorld eScan
Adware.Generic.559755
17.0.0.144

NANO AntiVirus
Trojan.Win32.InstallCore.crkdet
0.30.24.1636

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.16215

SUPERAntiSpyware
Adware.InstallCore/Variant
9318

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.2691
3.12.26.4

VIPRE Antivirus
InstallCore
40872

File size:
1 MB (1,100,528 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\downloads anteriores\messenger-plus--live-5500761-baixaki-32-bits-18102012185644.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:5nw+BRrC5HIrPt7uZCmysjiXj9XrFJXR4ZMPLAzXV9rho5akt6ZQQxqN:dhYUlukmyswjXJXa2PczC5QQQE

Entry address:
0xCA710

Entry point:
55, 8B, EC, 83, C4, F0, B8, B4, A6, 40, 00, E8, B5, F1, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
828 KB (847,872 bytes)

The file messenger-plus--live-5500761-baixaki-32-bits-18102012185644.exe has been seen being distributed by the following URL.