pgs3b4a.exe

Installer

The application pgs3b4a.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from storage.googleapis.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Product:
Installer

Description:
Installer-H

Version:
1.0.0.0

MD5:
320bfe4daf6cb8529ed5fa9473fa2cce

SHA-1:
7d50e36b3d97bcc26b5d0ed3794e49eaf6ab8621

SHA-256:
398839bbd9a3801e8ba52a0da7316d241241a4758f026af8726e85d1d6546898

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 3:09:10 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.Gen
7.11.218.126

avast!
MSIL:Downloader-NG [PUP]
2014.9-150319

Baidu Antivirus
Adware.MSIL.Imali
4.0.3.15319

ESET NOD32
MSIL/Adware.Imali (variant)
9.11345

herdProtect (fuzzy)
2015.6.25.16

IKARUS anti.virus
PUA.MSIL.Downloader
t3scan.1.8.6.0

File size:
2.9 MB (3,071,488 bytes)

Product version:
1.0.0.0

Original file name:
FinalInstaller_dotnet4.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\pgs3b4a.exe

File PE Metadata
Compilation timestamp:
3/20/2015 2:35:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:oZFUj6kcZwzMgmjjTySlH4eBjMxXRhCsRlsqkN6:iEXc+zXmOaH4eZMxPRlsqkN

Entry address:
0x2CFF7E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.4725

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.8 MB (2,940,928 bytes)

The file pgs3b4a.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove pgs3b4a.exe - Powered by Reason Core Security