openoffice - chip-downloader.exe

OCSClient

CHIP Digital GmbH

The application openoffice - chip-downloader.exe by CHIP Digital GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Covus installer. With this installer, users are expecting to download the free Apache OpenOffice but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
CHIP Digital GmbH  (signed and verified)

Product:
OCSClient

Version:
1.00

MD5:
13828bc7c69408c8b4624b01758dffd2

SHA-1:
309099abb87ec503df64ecfc52c4105aadf78d02

SHA-256:
a978e43b641f83fee44d280ae1c8a2e720e785feb34e3a2c9e8f918e672d606f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 1:02:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.2.3.3

File size:
600.4 KB (614,784 bytes)

Product version:
1.00

Original file name:
ocsclient.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus

Language:
English (United States)

Common path:
C:\users\{user}\downloads\openoffice - chip-downloader.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/26/2013 1:00:00 AM

Valid to:
11/27/2014 12:59:59 AM

Subject:
CN=CHIP Digital GmbH, O=CHIP Digital GmbH, STREET=St.-Martin-Str. 66, L=Munich, S=Bavaria, PostalCode=81541, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
360BEAFE1EBBCC59FBA31179BE3192C0

File PE Metadata
Compilation timestamp:
11/27/2013 1:28:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:fKWlw1Dx+lASQfCEv2YUMNJlaJuNlK17Y4c83fhysVufBn597NX2b:f7lw1DxS5QfXeYU43fiysgfBnnl2b

Entry address:
0x1620

Entry point:
68, 08, F6, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, EF, 4E, 90, D9, AA, 0A, CD, 43, 91, 50, 46, 79, E4, 37, D4, 82, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4F, 43, 53, 43, 6C, 69, 65, 6E, 74, 00, 6E, 64, 72, 65, 5C, 44, 00, 00, 00, 00, FF, CC, 31, 00, 03, 23, 5A, 55, 3A, 3C, E0, 07, 47, B3, 35, 82, 3C, 05, 78, AE, A7, 47, FF, BF, 0B, 62, DE, 67, 44, A8, 40, C9, 76, C0, F9, 23, 95, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
96 KB (98,304 bytes)

Remove openoffice - chip-downloader.exe - Powered by Reason Core Security