minecraft181-setup.exe

Zoobam

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application minecraft181-setup.exe by Zoobam has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the Tightrope WebInstall installer. The installer is marketed through download protals and search ads as Minecraft but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Zoobam  (signed and verified)

MD5:
3dfbf878093d7614ef501e5b917086f1

SHA-1:
f4b7dd31bc66e28e11e95d7d1cb6e9f057b7fe59

SHA-256:
35fc87ea2d7910d8abe057eb6e1a69298f90c28277fb3dc96c8d21c859385121

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 6:58:00 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
ADWARE/Adware.Gen
7.11.210.156

avast!
Win32:Adware-gen [Adw]
150129-1

AVG
Generic
2016.0.3196

Clam AntiVirus
Win.Adware.Downloadadmin
0.98/21511

Dr.Web
Trojan.Vittalia.14
9.0.1.05190

ESET NOD32
Win32/DownloadAdmin.H potentially unwanted application
7.0.302.0

F-Secure
Adware:W32/WebInstallBundle
5.13.68

NANO AntiVirus
Riskware.Win32.Downware.djahkt
0.30.0.65070

Reason Heuristics
PUP.Installer.Tightrope
15.2.16.20

Sophos
PUA 'DownloadAdmin' (of type Adware)
5.10

Vba32 AntiVirus
Downloader.Agent
3.12.26.3

VIPRE Antivirus
Threat.4783369
36694

File size:
651.8 KB (667,480 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tightrope WebInstall (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\My documents\downloads\minecraft181-setup.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
10/15/2014 10:27:59 PM

Valid to:
10/15/2017 10:27:59 PM

Subject:
CN=Zoobam, O=Zoobam, L=Kirkland, S=Washington, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4EA9D31E75E043

File PE Metadata
Compilation timestamp:
7/15/2014 12:29:31 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:jFdchfMAUeQEh/mYMlpmlaUdAU1LGnn/S62eUsGSGEbSxe8np:jaUWQYM7emU1Cnn/T7UsG3ECBn

Entry address:
0x3345

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2E, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1F, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0D, 24, 00, 00...
 
[+]

Entropy:
7.9711

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file minecraft181-setup.exe has been seen being distributed by the following URL.

Remove minecraft181-setup.exe - Powered by Reason Core Security