newtab_setup.exe

Boris Vladimirovich BOBOVSKY

The setup package is an adware installer (using InstalleRex) that will deploy with little or no user consent adware offerings including but not limited to browser extensions (add-ins, toolbars) that will inject various forms of advertising in the user's browser. The application newtab_setup.exe by Boris Vladimirovich BOBOVSKY has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the WebPick InstalleRex installer.
Publisher:
Boris Vladimirovich BOBOVSKY  (signed and verified)

MD5:
1d2e290ef51bc048c0d3b34a9508b7a2

SHA-1:
308d919bc4aeb0391844a6e1054da31653ce23bb

SHA-256:
4a2988dc3434d4a0843edf5d59005275161e3204f62c4698aad30882d3955d72

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional adware products (monetized browser extensions, ad injectors) in the installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/10/2024 12:18:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick.BorisVladimirovichBOBOVSKY.Bundler (M)
16.2.14.4

File size:
1.3 MB (1,328,592 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
WebPick InstalleRex

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\addons\newtab_setup.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
12/27/2013 1:31:44 PM

Valid to:
12/27/2014 1:31:44 PM

Subject:
E=bob@borr.info, CN="Open Source Developer, Boris Vladimirovich BOBOVSKY", O=Boris Vladimirovich BOBOVSKY, C=UA

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
1ADBC4E5D3604FB9725702528437E82A

File PE Metadata
Compilation timestamp:
9/9/2013 10:07:55 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:4Lz++NGw21vSe1OHk1wJG+/bf1H3yYuqxCeOJwrzpiNuHoJcvQLGmuaZuzRRp7Mz:4Lv4w21H1OEW8w1PXCMzpGuH7v09SlhC

Entry address:
0xD5B4

Entry point:
E8, 72, 4F, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 38, C0, 41, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 3C, C0, 41, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, 09, 19, 00, 00, 85, C0, 75, 06, B8, A0, C1, 41, 00, C3, 83, C0, 08, C3, E8, F6, 18, 00, 00, 85, C0, 75, 06, B8, A4, C1, 41, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Entropy:
7.9376  (probably packed)

Code size:
88 KB (90,112 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to i1.stylefun.info  (198.7.61.118:80)

TCP (HTTP):
Connects to dl.softservers.net  (184.154.145.171:80)

TCP (HTTP):
Connects to c1.getapplicationmy.info  (54.201.215.30:80)

Remove newtab_setup.exe - Powered by Reason Core Security