minecraft_game_downloader.exe

TRUSTED INSTALL SOFTWARE

The application minecraft_game_downloader.exe by TRUSTED INSTALL SOFTWARE has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tomorrow Software Installer installer. The installer is marketed through download protals and search ads as Minecraft but will also install additional software offers which include adware, PUPs and browser toolbars. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from files4.downloadnet1013.com.
Publisher:
Open Software Installer  (signed by TRUSTED INSTALL SOFTWARE)

Product:
Open Software Installer

Version:
2.2.2.5

MD5:
715686d75b535358dfb1ee5d1ecef112

SHA-1:
dcbccd8341b35d53b7c789105da1f5bd2b70dd7b

SHA-256:
d29b701a758c6f6959bff8b6e5db25f1b685b5ef95c81bfb442d77b38005d1be

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 7:22:28 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TomorrowSoftware.TRUSTEDI.Bundler (M)
16.4.12.9

File size:
875.2 KB (896,184 bytes)

Product version:
2.2.2.5

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tomorrow Software Installer

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\minecraft_game_downloader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/9/2015 7:00:00 PM

Valid to:
6/9/2016 6:59:59 PM

Subject:
CN=TRUSTED INSTALL SOFTWARE, O=TRUSTED INSTALL SOFTWARE, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2A889382754355CE927EAE3A2EA732CB

File PE Metadata
Compilation timestamp:
8/5/2014 12:35:27 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:ktMLKmtvPyHu7y1enyHy9pNg4W7HM8ocN+2QHCyt:aiKmHyOLyDp7s8VQB

Entry address:
0xC822

Entry point:
E8, 3C, 05, 00, 00, E9, 57, FD, FF, FF, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, A8, 4B, 41, 00, 89, 0D, A4, 4B, 41, 00, 89, 15, A0, 4B, 41, 00, 89, 1D, 9C, 4B, 41, 00, 89, 35, 98, 4B, 41, 00, 89, 3D, 94, 4B, 41, 00, 66, 8C, 15, C0, 4B, 41, 00, 66, 8C, 0D, B4, 4B, 41, 00, 66, 8C, 1D, 90, 4B, 41, 00, 66, 8C, 05, 8C...
 
[+]

Entropy:
7.9584  (probably packed)

Code size:
51.5 KB (52,736 bytes)

The file minecraft_game_downloader.exe has been seen being distributed by the following URL.

Remove minecraft_game_downloader.exe - Powered by Reason Core Security