openofficesuite-setup.exe

Download Admin

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application openofficesuite-setup.exe by Download Admin has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the Tightrope WebInstall installer. The installer is marketed through download protals and search ads as the free Apache OpenOffice but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Download Admin  (signed and verified)

MD5:
4904d35768e9e69c909efc8ec6caaf51

SHA-1:
922d6f4008d68fa774354ca2d470fc8e7b437a8a

SHA-256:
8418ca97f6a3c7fb716e6a96cf584aff99e0d41dae1c692e64227c1b4c12cd92

Scanner detections:
3 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 1:57:28 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.411
9.0.1.0185

herdProtect (fuzzy)
2015.7.4.21

Reason Heuristics
PUP.Bundler.Tightrope
15.3.30.22

File size:
32.7 MB (34,287,432 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tightrope WebInstall (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\openofficesuite-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/3/2010 1:00:00 AM

Valid to:
5/30/2013 12:59:59 AM

Subject:
CN=Download Admin, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Download Admin, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
29529B0D185F8525A92A866D4A38DA3A

File PE Metadata
Compilation timestamp:
6/22/2012 7:07:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:hxpJkhs2pgWjJOnTyQeZlD9FXJIGlcjIBCbc40QwzpDNG1CekI4:TpShs0rJoeXXDcsAbc4WRNGIw4

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
0.2773

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove openofficesuite-setup.exe - Powered by Reason Core Security