mytopfreegames_unlockgames.exe

Installer

OpenInstall, Inc.

The application mytopfreegames_unlockgames.exe by OpenInstall has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from c10891052.r52.cf2.rackcdn.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
OpenInstall   (signed by OpenInstall, Inc.)

Product:
Installer

Version:
1,18,0,2210

MD5:
904c2bc5b1f2335f2bb6440bd3817624

SHA-1:
2b5d2062c4cee9366380401ce69c29911b9c82df

SHA-256:
060357bcea2acb30bf2457548ca8387c591dc3a5ebe32fce87988840a1dd6005

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Includes Open Install, an installer which bundles legitimate programs with offers for additional 3rd-party applications that may be unwanted by the user.

Analysis date:
4/19/2024 7:37:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OpenInstall.Installer (M)
16.6.13.8

File size:
333.1 KB (341,144 bytes)

Product version:
1,18,0,2210

Copyright:
Copyright © 2012

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\mytopfreegames_unlockgames.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/20/2011 7:00:00 PM

Valid to:
1/24/2013 7:00:00 AM

Subject:
CN="OpenInstall, Inc.", O="OpenInstall, Inc.", L=San Francisco, S=California, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07AE9941492080181D2477353500DE05

File PE Metadata
Compilation timestamp:
3/10/2012 10:50:25 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:JSQfhYCjILkOUvJyWRJFLnWOuqWGK7HneaUhKl24vCHD98YVyU7FwmjQ:sQfqwuUvJyWRf7WZLoh/1j+YVFFwoQ

Entry address:
0xDB570

Entry point:
60, BE, 00, D0, 49, 00, 8D, BE, 00, 40, F6, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.3724

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
252 KB (258,048 bytes)

The file mytopfreegames_unlockgames.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove mytopfreegames_unlockgames.exe - Powered by Reason Core Security