ShapeCollage-2.5.3-Setup.exe

Shape Collage

Shape Collage Inc.

The application ShapeCollage-2.5.3-Setup.exe, “Shape Collage Setup for Windows” by Shape Collage has been detected as a potentially unwanted program by 5 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from www.commentcamarche.net and multiple other hosts.
Publisher:
Shape Collage Inc.  (signed and verified)

Product:
Shape Collage

Description:
Shape Collage Setup for Windows

Version:
2.5.3

MD5:
77c30dc94a488feb6059f9c83bb1a16a

SHA-1:
a3decadf9db2eedd5c0e0b3aac7cf022f799de20

SHA-256:
9e6ac1510f2d195aeea26a3719ca827454556aafe8a3f7ad440f126d8a49b96e

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/26/2024 6:37:05 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
7.9190

Fortinet FortiGate
Riskware/OpenCandy
8/2/2013

Malwarebytes
PUP.Optional.OpenCandy
v2013.11.25.04

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
23.00.65.131208

Vba32 AntiVirus
TrojanDownloader.Genome
3.12.24.3

File size:
1 MB (1,074,928 bytes)

Product version:
2.5.3

Copyright:
Copyright Shape Collage Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\shapecollage-2.5.3-setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/11/2012 8:00:00 PM

Valid to:
10/12/2013 7:59:59 PM

Subject:
CN=Shape Collage Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Shape Collage Inc., L=Vancouver, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
67573CFB94D6FA8B18D2651A60D7FB6A

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:K5f9f+EIYOiqumAzlU9PZwkj+rKLf/8JF0n0fy8FxUG9o93k:aE7YOiqumAzC9PZwk9moQ3xzOq

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Code size:
23 KB (23,552 bytes)

The file ShapeCollage-2.5.3-Setup.exe has been seen being distributed by the following 2 URLs.

Remove ShapeCollage-2.5.3-Setup.exe - Powered by Reason Core Security