SandboxieInstall.exe

Sandboxie

Invincea, Inc.

This is a self-extracting archive and installer. The file has been seen being downloaded from 123.briian.com and multiple other hosts.
Publisher:
Sandboxie Holdings, LLC  (signed by Invincea, Inc.)

Product:
Sandboxie

Description:
Sandboxie Installer

Version:
5.06

MD5:
7518f8032448a0b17cf41db2337f89f2

SHA-1:
1c47e7154f0d9ab8d997ee69321216f79ad3904d

SHA-256:
bb7518c15c979db728f4418bce88444710f5311dc25d998006ca53913df36c40

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
9/24/2017 10:17:43 PM UTC  (today)

File size:
8.1 MB (8,518,280 bytes)

Product version:
5.06

Copyright:
Copyright © 2004-2015 by Sandboxie Holdings, LLC

Original file name:
SandboxieInstall.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\sandboxieinstall.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/18/2015 2:00:00 AM

Valid to:
4/17/2018 2:00:00 PM

Subject:
CN="Invincea, Inc.", O="Invincea, Inc.", L=Fairfax, S=Virginia, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
05DE398F4AC5D00E254C9295F336CF4F

File PE Metadata
Compilation timestamp:
10/22/2015 8:16:21 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:1zoQVEpr63GFXHyHfL4WZ3QXO8Y2TXxCUGwrISrSYaLc0mnb0XUySBYX384uDvLB:1goccfcCQ3Y2TXkgrdrt0mbVHYXsJDN7

Entry address:
0x14B2

Entry point:
E8, 45, 17, 00, 00, E9, 1E, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 2A, 83, 78, 10, 03, 75, 24, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 05, E8, 95, 17, 00, 00, 33, C0, 5D, C2, 04, 00, 68, BC, 14, 40, 00, FF, 15, 64, 80, 40, 00, 33, C0, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 33, C0, EB, 0F, 85, C0, 75, 10, 8B, 0E, 85, C9, 74, 02, FF, D1, 83, C6, 04, 3B, 75, 0C, 72, EC, 5E, 5D, C3, 8B, FF...
 
[+]

Entropy:
7.9888  (probably packed)

Code size:
25 KB (25,600 bytes)

The file SandboxieInstall.exe has been discovered within the following program.

Free Youtube To Video Converter  by Media Freeware
The installer uses the OutBorwse download manager to bundle additional adware during install including Conduit Search Protect, Yontoo PlurPush, SysTweak and other toolbars and potentially unwanted software utilities.
www.mediafreeware.com
88% remove it
 
Powered by Should I Remove It?

The file SandboxieInstall.exe has been seen being distributed by the following 39 URLs.

http://123.briian.com/forum.php?mod=attachment&aid=OTc1MnxhODVlY2U5MHwxNDY1MjA2MTE4fDB8NTk=

http://dw1.uptodown.com/dwn/pZzKC31dU2pEaZdP9a6Hq2IFYGm3ilv6aC9ukK37A_lMAnlVMIV1pJ2M2hUWaIZMvB80sbyHyPyyTtys_Mj_bi5nPijKv5DYhFfByaqDabTzQgcOXBnh94TbYF3G_y-5/.../sandboxie-5-06-multi-win.exe

http://download1017.mediafire.com/k39uxp3g6rvg/.../SandboxieInstall(2).exe

http://filehippo.com/es/download/file/.../

http://cafeattach.naver.net/46d35aeaffa3a27e50b3d4e0d93947399fcd32d3d9/20160204_198_cafefile/.../SandboxieInstall.exe

http://123.briian.com/forum.php?mod=attachment&aid=OTc1MnwxN2VkZGY3YXwxNDYyNzc3ODA3fDB8NTk=

http://filehippo.com/es/download/file/.../

http://indir.gezginler.net/i/17550/.../

Latest 30 of 39 download URLs

Scan SandboxieInstall.exe - Powered by Reason Core Security