pal_install_beta_r1111_2.exe

Paltalk Messenger Setup

Paltalk.com

The application pal_install_beta_r1111_2.exe by Paltalk.com has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This version of the installer will bundle the Ask.com Toolbar, a potentially unwanted web browser extension. The file has been seen being downloaded from downloads.paltalk.com and multiple other hosts.
Publisher:
AVM Software Inc.  (signed by Paltalk.com)

Product:
Paltalk Messenger Setup

Version:
11,5,577,16815

MD5:
a9428c411c0208f43ae1e531341720bb

SHA-1:
8ea7e8cbdf4e4073d31c01bf9144bf064c1b75da

SHA-256:
5f1389281b20ee511b6c6755a0f4b0efee08e8f0a9ad6e9d6f081ca6eade8f7f

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Bundles that Ask.com toolbar as a third-party offer, a web browser extension that may modify a user's search and home pages.

Analysis date:
4/26/2024 10:59:40 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
Win32/Bundled.Toolbar.Ask.G potentially unsafe application
7.0.302.0

Reason Heuristics
PUP.Ask.Toolbar.Bundled
16.3.1.0

File size:
2 MB (2,100,984 bytes)

Product version:
11,5,577,16815

Copyright:
Copyright 1999 - 2014

Original file name:
paltalk_messenger_setup.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\pal_install_beta_r1111_2.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/10/2012 8:00:00 PM

Valid to:
5/11/2015 7:59:59 PM

Subject:
CN=Paltalk.com, O=Paltalk.com, STREET=PO Box 7528, STREET=Church Street Station, L=New York, S=NY, PostalCode=10008, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
729EE4CEB28A90BBF4B6792577437EE2

File PE Metadata
Compilation timestamp:
9/5/2011 10:16:19 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:sgh/VoZ51I0vIx+VSbgt63XRNFgJoVsgxTwlAjmbGekk1mPKTwlI:ZVoZa40+637yJoVcJGha

Entry address:
0x384F

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 28, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 24, 92, 40, 00, FF, 15, 84, 81, 40, 00, 68, 0C, 92, 40, 00, 68, C0, AD, 46, 00, E8, 18, 27, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Entropy:
7.9879

Packer / compiler:
Nullsoft install system v2.x

Code size:
27.5 KB (28,160 bytes)

The file pal_install_beta_r1111_2.exe has been seen being distributed by the following 30 URLs.

http://downloads.paltalk.com/download/.../pal_install_u41555387_a729_r109744_p114.exe

http://www.downloadpresentcity.com/I49bL4dRhgbTtLCPOgsu f9_tbFeVYWPlSES8Z60so3_Lj_82DxNrqXFOqK78ua7UnJN0Jh791StAR8vRxHzXAw2hMnziv8YhZ4MDl cPZ6obQc6DN9lCh5Uj7r7lSDYVf3t4U ynVuxTg5puChfc6qhQy2YkIdpVPSOX8uQQBGw8revi38=-Gx0DAGTKTaosOEH0XhGxNIx6skhgIgfsbTHEfBJ7bxx4ssbIzyIw3wVYqqk czB98F6rnrseZtm91sqF3a0Rjp qZKuOsLLJNIL5aiRUQa67d_LXVWBtnuqX9vjAG45t2PupC6ZjoapNertIkI2CMcLRJorW_Mk89KiPWvj0AetN5TUs5fGaPKyFPjY u4LO6PcBP3g4AaEHAFkIz8aclC4FA_YV_fCOzMmFc8_dtr3UM4sNsltfqGTF9YH0ZAeJCKnbRJ9rYbZxsGfUPIQunzU5NYkSYHtqNu6k QzcIDwbOxfX2378rrPjmH2gWzwNSKC5JrRrZH8y8YVRmzKMfQnP87nlb45udy95Qq_7otLgocfccET3yu7sTRy ZKGijxGEiChqBDMyVMcoDh2hmsvJ8k6GnYzbFhV19qkXQ6p6kGZ8gRS8m0ufz4uRHBe4S ppZvpq7VdvUEbc2rl7 z2CnF95GL6K2uDIxadD5lIIiev4Lrwy_CaJCjR9D5zu1CY3SSPnjogNfcGALVV3CXaxxB3xnDxTX4tY2o6uuFWDc2lf3QKi2KeEjQ9NTvbmCq5MEun0SWuoqpSugu1bDlVXftF77ZDSE3MwVc SyZGX88VKVp T8QxZm373zNc0yipzobe6iMEechSd cdbVWeXuydow2qRgzq98EvgLa808YK8h5hS5vsyBOCTlDhV5pKrvq1db2twB8tPGXFZVvQr6nhI9PBN6AVHa68BwWlW1qsab70ugoZ0tiOfiSZkbsZKYhrtoW owxWW

http://downloads.paltalk.com/download/.../pal_install_ar_u41667871_a729_r109723_p153.exe

http://downloads.paltalk.com/download/.../pal_install_u41632583_a729_r109812_p159.exe

http://downloads.paltalk.com/download/.../pal_install_ar_u41675292_a729_r109723_p153.exe

http://download.paltalk.com/download/.../pal_install_ar_r1111.exe

http://downloads.paltalk.com/download/.../pal_install_u41510791_a729_r109727_p128.exe

http://download.paltalk.com/download/.../pal_install_r1111.exe

Latest 30 of 30 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cache.google.com  (103.9.112.143:80)

TCP (HTTP):
Connects to a23-57-240-115.deploy.static.akamaitechnologies.com  (23.57.240.115:80)

TCP (HTTP):
Connects to a104-99-163-28.deploy.static.akamaitechnologies.com  (104.99.163.28:80)

TCP (HTTP):
Connects to a104-89-28-244.deploy.static.akamaitechnologies.com  (104.89.28.244:80)

Remove pal_install_beta_r1111_2.exe - Powered by Reason Core Security