setupcasino_316317_en.exe

Playtech PLC

The application setupcasino_316317_en.exe, “Casino.com Installer” by Playtech PLC has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. The file has been seen being downloaded from www.zarabiajpieniadze.com and multiple other hosts.
Publisher:
Casino.com  (signed by Playtech PLC)

Product:
Casino.com

Description:
Casino.com Installer

Version:
1.1.1.28

MD5:
7ea7753a37b655c915d3d0268152484c

SHA-1:
4e7dd7585ace4c2e5e5e48fa657d3a21b71f8f73

SHA-256:
e9c1fbcbb2bc5f13de6707b539df5061a85d6d0e6b8aa7dda5df2bc119a61a70

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/26/2024 6:15:06 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Crossrider.PlaytechPLC.Installer.Meta (M)
15.12.30.16

File size:
863.7 KB (884,472 bytes)

Copyright:
Copyright 2014

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setupcasino_316317_en.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/20/2014 8:00:00 AM

Valid to:
1/16/2015 7:59:59 AM

Subject:
CN=Playtech PLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Playtech PLC, L=Douglas, S=IM, C=IM

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
764E6DB88B018BFEBD8F7B533DC3A6D3

File PE Metadata
Compilation timestamp:
12/4/2012 9:55:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
24576:BYno+OWrxR2t/eICJNqGoL3jBgzbvuxIfaL2xFmgu+teWQUpEIF:BVNKxotZ6nW3jAuxIyL2xFmbYeqj

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9137  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file setupcasino_316317_en.exe has been seen being distributed by the following 8 URLs.

http://www.zarabiajpieniadze.com/.../?c=casino

Remove setupcasino_316317_en.exe - Powered by Reason Core Security