nero_burning_rom_he.exe

The application nero_burning_rom_he.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from safe.to.download.downloadastro.com and multiple other hosts.
MD5:
af5e4f23adac3a5c8558eddc8e4e89a0

SHA-1:
f9deb38188b8cf8f04d196b7c6881cff4d468bff

SHA-256:
77474a81cb3e607ce9ca99c7c754292b5486ee521561d8dba477df58c9e7eff2

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/25/2024 3:22:26 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/InstallCore.AT.13
7.11.112.90

Bkav FE
W32.Clodc7b.Trojan
1.3.0.4415

Dr.Web
Trojan.Packed.24524
9.0.1.0138

ESET NOD32
Win32/InstallCore.FD
10.9025

F-Prot
W32/InstallCore.R.gen
v6.4.7.1.166

Malwarebytes
v2016.05.17.03

McAfee
Artemis!AF5E4F23ADAC
5600.6396

Reason Heuristics
PUP.InstallCore.ENG (M)
16.5.17.15

SUPERAntiSpyware
9138

VIPRE Antivirus
InstallCore.b
23186

File size:
663.8 KB (679,736 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\nero_burning_rom_he.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:mZMJfsGGgMccNzVhzC5W7zD7UMyPlIIZUv/rgY2DfLo2+NbHy0h0tD5R:GMJfs1gxcVVhzMW7zDIFNp0rgxbLo9VM

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.8001

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file nero_burning_rom_he.exe has been seen being distributed by the following 3 URLs.

http://safe.to.download.downloadastro.com/minecraft_he.exe

http://api.downloadastro.com/api/downloader/.../he?callback=jsonpCallbackDownload&_=1384177339

Remove nero_burning_rom_he.exe - Powered by Reason Core Security