openofficesuite-setup.exe

Trusted Install Software

The application openofficesuite-setup.exe by Trusted Install Software has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tomorrow Software Installer installer. The installer is marketed through download protals and search ads as the free Apache OpenOffice but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Trusted Install Software  (signed and verified)

Product:
Trusted Install Software

Version:
78.1.3.9410

MD5:
15bc26378b8f8e03cb1d49a7f6d1be6b

SHA-1:
694abb49366a503cfb962ef792b8404c4d7a68da

SHA-256:
ca069c39ae4d81624ce111c9e3e52c9648b9b0b509d5602a847a2f76ab6be00d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/5/2024 3:48:06 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TomorrowSoftware (M)
16.8.20.23

File size:
882.6 KB (903,824 bytes)

Product version:
78.1.3.9410

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tomorrow Software Installer

Language:
English (United States)

Common path:
C:\users\{user}\downloads\openofficesuite-setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
10/30/2015 4:42:38 PM

Valid to:
9/16/2016 8:38:38 PM

Subject:
CN=Trusted Install Software, O=Trusted Install Software, L=San Francisco, S=California, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2BDBC9B532830DBB

File PE Metadata
Compilation timestamp:
12/1/2014 2:08:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:5jsS/ptd4lunF+LAbGtO19r5GzknhTEiYgeUvYX:9sSTd4lF8P19r5GdNfyk

Entry address:
0x1333

Entry point:
E8, D8, C1, 00, 00, E9, D6, BA, 00, 00, CC, CC, CC, 53, 55, 56, 57, 8B, 7C, 24, 14, 33, F6, 85, FF, 7E, 27, 8B, 5C, 24, 18, 8B, 2D, 9C, F0, 40, 00, EB, 06, 8D, 9B, 00, 00, 00, 00, A1, C4, AC, 44, 00, 8B, 0C, B3, 50, 51, FF, D5, 85, C0, 74, 3D, 46, 3B, F7, 7C, EB, 8B, 15, EC, AA, 44, 00, A1, 5C, AB, 44, 00, 8B, 0D, D4, AB, 44, 00, 52, 50, 51, 8D, 54, 24, 20, 52, C7, 44, 24, 24, FF, FF, FF, FF, E8, 95, 59, 00, 00, 83, C4, 10, 85, C0, 75, 0B, 8B, 44, 24, 14, 50, FF, 15, B4, F0, 40, 00, 5F, 5E, 5D, 5B, C3, CC...
 
[+]

Entropy:
7.9641  (probably packed)

Code size:
53.5 KB (54,784 bytes)

Remove openofficesuite-setup.exe - Powered by Reason Core Security