monografando-10-baixaki-32-bits.exe

The application monografando-10-baixaki-32-bits.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. The program is a setup application that uses the installCore installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from s3.amazonaws.com and multiple other hosts.
MD5:
a97203467ee765e40edde565291afc44

SHA-1:
0497668d5900e1dd2ff47361e4d14b0f7bcd5d05

SHA-256:
ab3f61ce99f2306b45df26d0f2554c32670b00eace24d1e23e72844e4a030737

Scanner detections:
20 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 6:09:12 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

AhnLab V3 Security
PUP/Win32.InstallCore
2015.03.23

Avira AntiVirus
Adware/InstallCo.AB
7.11.219.36

Comodo Security
Application.Win32.InstallCore.AB
21499

Dr.Web
Adware.InstallCore.107
9.0.1.0161

ESET NOD32
Win32/InstallCore.BL potentially unwanted
9.11359

F-Prot
W32/InstallCore.R3.gen
v6.4.7.1.166

G Data
Win32.Application.InstallCore.CJ
15.6.25

IKARUS anti.virus
Backdoor.Hupigon
t3scan.1.8.6.0

McAfee
Artemis!A97203467EE7
5600.6738

NANO AntiVirus
Riskware.Win32.InstallCore.dcnboc
0.30.8.659

Qihoo 360 Security
Win32/Virus.Adware.dc7
1.0.0.1015

Reason Heuristics
PUP.Bundler.InstallCore
15.6.10.18

Rising Antivirus
PE:Malware.InstallCore!6.4
23.00.65.15608

Sophos
Generic PUA AE
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Hupigon
9821

Trend Micro House Call
TROJ_SPNV.03L313
7.2.161

Trend Micro
TROJ_SPNV.03L313
10.465.10

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
InstallCore
38666

File size:
621.4 KB (636,280 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\monografando-10-baixaki-32-bits.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:99yMJfsYBZ2EGBvs/3BvHFlIupjVTCDgC6Y4u99+GUJe25ftHuQ2G1jp3B:99yMJfs8kVdQBvH7IupjVTCDgxTC9+Gm

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file monografando-10-baixaki-32-bits.exe has been seen being distributed by the following 2 URLs.

Remove monografando-10-baixaki-32-bits.exe - Powered by Reason Core Security