newtab_setup.exe

Pavel KRASNOV

This installer (utilizes the InstalleRex from WebPick) is designed to bundle additional software offerings such as adware and malware, mostly web browser extensions in the download manager, with minimal user consent. In most cases the setup process will install a browser extension for IE, Chrome and Firefox by default. The application newtab_setup.exe by Pavel KRASNOV has been detected as adware by 32 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address dl.softservers.net on port 80 using the HTTP protocol.
Publisher:
Pavel KRASNOV  (signed and verified)

MD5:
80c5ab4956db5a3d4a971792ba0aafed

SHA-1:
ad4fc4b8d84f08afa5eb9477f734161668e3847f

SHA-256:
ccf5fe3e3347b5cd3e8c9f319fa15a452d80489ef380de65836f317c068b4e93

Scanner detections:
32 / 68

Status:
Adware

Explanation:
Bundles additional adware offers in the installer/setup process.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/18/2024 3:30:33 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Dropper.101
6373653

Agnitum Outpost
PUA.MultiPlug
7.1.1

Avira AntiVirus
ADWARE/Adware.Gen
3.6.1.96

avast!
Win32:PUP-gen [PUP]
150320-0

AVG
Adware Generic5.AMTA
2014.0.4311

Bitdefender
Gen:Variant.Adware.Dropper.101
1.0.20.430

Clam AntiVirus
Win.Adware.Dropper-3
0.98/21511

Comodo Security
Application.Win32.Multiplug.GETF
21554

Dr.Web
Trojan.MulDrop5.7854
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Dropper.101
9.0.0.4799

ESET NOD32
Win32/AdWare.MultiPlug.R application
7.0.302.0

Fortinet FortiGate
Riskware/Generic.AC.28568
3/27/2015

F-Prot
W32/A-23e5d9bf
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Dropper
5.13.68

G Data
Gen:Variant.Adware.Dropper.101
15.3.25

IKARUS anti.virus
Virus.Script
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.202.15399

Kaspersky
not-a-virus:WebToolbar.Win32.Cossder
14.0.0.2284

Malwarebytes
PUP.Optional.Installrex
v2015.03.27.06

McAfee
Program.PUP-FEI
16.8.708.2

Microsoft Security Essentials
Threat.Undefined
1.195.475.0

MicroWorld eScan
Gen:Variant.Adware.Dropper.101
16.0.0.258

NANO AntiVirus
Riskware.Win32.MegaSearch.csvfny
0.30.8.659

Norman
Gen:Variant.Adware.Dropper.101
03.12.2014 13:20:04

Panda Antivirus
Trj/Genetic.gen
15.03.27.06

Quick Heal
AdWare.MultiPlug.r5
3.15.14.00

Reason Heuristics
PUP.Bundler.WebPick
15.3.27.6

Rising Antivirus
PE:Malware.Adware!6.1277
23.00.65.15325

Sophos
MultiPlug
4.98

Vba32 AntiVirus
Adware.MegaSearch
3.12.26.3

VIPRE Antivirus
Threat.4786450
38552

Zillya! Antivirus
Trojan.Black.Win32.16669
2.0.0.2118

File size:
1.5 MB (1,540,664 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
WebPick InstalleRex

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\addons\newtab_setup.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
1/17/2014 8:46:29 AM

Valid to:
1/17/2015 8:46:29 AM

Subject:
E=pavel0125@hotmail.com, CN="Open Source Developer, Pavel KRASNOV", O=Pavel KRASNOV, C=RU

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
145B82E22CCF1D1A2268198D76B51075

File PE Metadata
Compilation timestamp:
1/27/2014 11:38:36 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:jpD4YZMvJ1iljWWOyt8EhlLo3vjb4djQIv+IGbAxf2qYP2/BgiWh/X3JB8wA61iT:N4YZpxtSEhl8/jyjQy+IGb4SfJB8wM

Entry address:
0xE3DB

Entry point:
E8, 7E, 44, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, C8, ED, 41, 00, E8, DF, 12, 00, 00, E8, CB, 0F, 00, 00, 0F, B7, F0, 6A, 02, E8, 11, 44, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 96, 01, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
89 KB (91,136 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to i1.stylefun.info  (198.7.61.118:80)

TCP (HTTP):
Connects to dl.softservers.net  (184.154.145.171:80)

TCP (HTTP):
Connects to c1.getapplicationmy.info  (54.201.215.30:80)

Remove newtab_setup.exe - Powered by Reason Core Security