openoffice - chip-installer.exe

CHIP Digital GmbH

The application openoffice - chip-installer.exe, “CHIP Secured Installer” by CHIP Digital GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Covus installer. The installer is marketed through download protals and search ads as the free Apache OpenOffice but will also install additional software offers which include adware, PUPs and browser toolbars. The file has been seen being downloaded from x.chip.de.
Publisher:
CHIP Digital GmbH  (signed and verified)

Description:
CHIP Secured Installer

Version:
2.1.3.1

MD5:
0e6be44bcfea9c70fb63f88c6b665d03

SHA-1:
46ee8fedc8c6b986fa4e9395842b997b79e481c9

SHA-256:
f1af2c69ce970797eaac0155fceea1ad1b7ee031e4946c2e9fe28a8369c2eb87

Scanner detections:
1 / 68

Status:
Potentially unwanted

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
7/13/2020 5:06:50 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ChipDigital.Bundler (M)
17.3.16.13

File size:
1.4 MB (1,496,584 bytes)

Product version:
2.1.3.1

Copyright:
Copyright © 2016 Chip Digital GmbH

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus

Language:
German (Germany)

Common path:
C:\users\{user}\downloads\openoffice - chip-installer.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/27/2016 1:00:00 AM

Valid to:
1/27/2017 12:59:59 AM

Subject:
CN=CHIP Digital GmbH, OU=Download Development, O=CHIP Digital GmbH, STREET=St.-Martin-Strasse 66, L=Munich, S=Bavaria, PostalCode=81541, C=DE

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B0564F3FBF54F6269517864BB24329FC

File PE Metadata
Compilation timestamp:
11/17/2016 3:16:08 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x1EE910

Entry point:
60, BE, 00, B0, 59, 00, 8D, BE, 00, 60, E6, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
336 KB (344,064 bytes)

The file openoffice - chip-installer.exe has been seen being distributed by the following URL.

http://x.chip.de/intern/dl/?url=http://www.chip.de/.../?lastchange=151120161207&pid=chipderedesign&cid=54383364&euid=0aa0b8ca1701f82201769669&source=BLUB2&browser=chrome&ref=&tid=39020&tname=Büro-Software&v=oct2015&pageLayout=withinstaller|e51

Remove openoffice - chip-installer.exe - Powered by Reason Core Security