mightymagoo_unlockgames.exe

Installer

OpenInstall, Inc.

The application mightymagoo_unlockgames.exe by OpenInstall has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from c10891052.r52.cf2.rackcdn.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
OpenInstall   (signed by OpenInstall, Inc.)

Product:
Installer

Version:
1,18,0,2210

MD5:
d37c13ede6c111e5e1f617166664eada

SHA-1:
f72d5dba4581ba5c199979d022a94959b188ad7c

SHA-256:
e50a859fbdfa826d308c6eefdd79793a40856f5110e123af0946e09f7445eb7e

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Includes Open Install, an installer which bundles legitimate programs with offers for additional 3rd-party applications that may be unwanted by the user.

Analysis date:
4/19/2024 7:59:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OpenInstall.Installer (M)
16.6.25.14

File size:
333.1 KB (341,136 bytes)

Product version:
1,18,0,2210

Copyright:
Copyright © 2012

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\mightymagoo_unlockgames.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/20/2011 9:00:00 PM

Valid to:
1/24/2013 9:00:00 AM

Subject:
CN="OpenInstall, Inc.", O="OpenInstall, Inc.", L=San Francisco, S=California, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07AE9941492080181D2477353500DE05

File PE Metadata
Compilation timestamp:
3/10/2012 12:50:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:xSQfhYCjILkOUvJyWRJFLnWOuqWGK7HneaUhKl24vCHD98YVyU7Fwmjs:kQfqwuUvJyWRf7WZLoh/1j+YVFFwos

Entry address:
0xDB570

Entry point:
60, BE, 00, D0, 49, 00, 8D, BE, 00, 40, F6, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
252 KB (258,048 bytes)

The file mightymagoo_unlockgames.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove mightymagoo_unlockgames.exe - Powered by Reason Core Security