mirovideoconverter_openinstall.exe

Participatory Culture Foundation

The application mirovideoconverter_openinstall.exe by Participatory Culture Foundation has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from icdn.mirovideoconverterfiles.com.
Publisher:
Participatory Culture Foundation  (signed and verified)

MD5:
1084f40fe769d2db29613d3d8937815c

SHA-1:
2582c925d192ab649b768dbe2bcf7eacb9b1e1c4

SHA-256:
74355b795b940b9659739a866f66f801a5d12fad75efa3cf10a6205363f86950

Scanner detections:
2 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/2/2024 9:05:47 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallCore.QL (variant)
8.10372

Reason Heuristics
PUP.ParticipatoryCultureFoundation.EE
14.9.7.19

File size:
797.9 KB (817,064 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\mirovideoconverter_openinstall.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
8/29/2014 8:00:00 PM

Valid to:
8/30/2015 7:59:59 PM

Subject:
CN=Participatory Culture Foundation, OU=IT, O=Participatory Culture Foundation, L=Boston, S=Massachusetts, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4218E962A32C9FE95E05126381ECC2FA

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:vAmvRCLzz5t9IdfcxXAf3yHW91a1nLyxqm8I2:vAmRCj57GtT1pxqmh2

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8236

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file mirovideoconverter_openinstall.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-154-109-8.eu-west-1.compute.amazonaws.com  (54.154.109.8:80)

TCP (HTTP):
Connects to hosted-by.leaseweb.com  (199.58.87.151:80)

TCP (HTTP):
Connects to ec2-54-191-59-48.us-west-2.compute.amazonaws.com  (54.191.59.48:80)

TCP (HTTP):
Connects to ec2-52-49-170-39.eu-west-1.compute.amazonaws.com  (52.49.170.39:80)

TCP (HTTP):
Connects to ec2-52-30-150-214.eu-west-1.compute.amazonaws.com  (52.30.150.214:80)

TCP (HTTP):
Connects to ec2-52-26-136-207.us-west-2.compute.amazonaws.com  (52.26.136.207:80)

TCP (HTTP SSL):
Connects to a118-215.98-188.deploy.akamaitechnologies.com  (118.215.98.188:443)

TCP (HTTP SSL):
Connects to a104-93-102-52.deploy.static.akamaitechnologies.com  (104.93.102.52:443)

Remove mirovideoconverter_openinstall.exe - Powered by Reason Core Security