setup.exe

Bundlore LTD

This is the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe, “Any Media Converter setup” by Bundlore has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Bundlore Downloader installer. The file has been seen being downloaded from deb.freevideodownloadsonline.com and multiple other hosts.
Publisher:
Any Media Converter  (signed by Bundlore LTD)

Product:
Any Media Converter

Description:
Any Media Converter setup

Version:
1.14

MD5:
ee6c082a6f8b5867a0ca3afcd7d0d78e

SHA-1:
c86332320622df282f6969c5b88a7302c14bff04

SHA-256:
89834a36e5b05f0c6629e76f44180346a49cb3dfd5853dcfb10df6d76ce8fb43

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/16/2018 3:25:31 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
AdInstaller.Bundlor
2017.0.2829

Dr.Web
Adware.Downware.514
9.0.1.049

ESET NOD32
Win32/Toolbar.Conduit
10.11056

G Data
Win32.Adware.Conduit
16.2.24

IKARUS anti.virus
PUA.Bundlore
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.191.14720

Norman
Bundlore.CERT
11.20160218

Panda Antivirus
PUP/Conduit.A
16.02.18.01

Reason Heuristics
PUP.Bundlore.AnyMediaConverter.Bundler (M)
16.2.18.13

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Wajam
36876

File size:
602.5 KB (616,952 bytes)

Copyright:
© Any Media Converter (Converter_I135B_AUTO_NICE_SIGNED_WITHPOST)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Bundlore Downloader (using Nullsoft Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/4/2012 9:00:00 PM

Valid to:
7/5/2014 8:59:59 PM

Subject:
CN=Bundlore LTD, O=Bundlore LTD, STREET=Beit Oved 9, L=Tel Aviv, S=Israel, PostalCode=67211, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0C7A8094C56AAFE39F3CA37C7F65AC84

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:ryX8HCqUPa/xXd3Vz2cV+d8lHvFd2a/BjgBp9/dtw0:ryUCTa5XdFz2HaPj2wsz+

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file setup.exe has been seen being distributed by the following 2 URLs.

Remove setup.exe - Powered by Reason Core Security