siinst-web.exe

Software Informer web installer

Softdeluxe Ltd.

The application siinst-web.exe by Softdeluxe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from software.informer.com and multiple other hosts. While running, it connects to the Internet address d3.16.e443.ip4.static.sl-reverse.com on port 80 using the HTTP protocol.
Publisher:
Softdeluxe Ltd.  (signed and verified)

Product:
Software Informer web installer

Version:
1.0.31.0

MD5:
11dc2601110f224e06888929c198ddd0

SHA-1:
d05b83dbe7fae39f5ddbf5ac34be7b5f673712eb

SHA-256:
4811b44cad5856bb698479f5b4f1ce0f4899cab657f786f5967baea906005050

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 11:57:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softdeluxe.Installer.Meta (M)
16.6.10.13

File size:
926.6 KB (948,848 bytes)

Product version:
1.0.31.0

Copyright:
Copyright (C) Softdeluxe Ltd., 2015

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\siinst-web.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/12/2013 3:00:00 AM

Valid to:
8/12/2016 2:59:59 AM

Subject:
CN=Softdeluxe Ltd., O=Softdeluxe Ltd., STREET="Universitetskaya St., 19", L=Dubna, S=Moscow region, PostalCode=141980, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2E75CC2B1043779E577FAA449BCE00A4

File PE Metadata
Compilation timestamp:
6/26/2015 1:28:19 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:eLDHeSwLeLfcp0c93GDPNy+T/oUygc5s2OEbFf:ADXcp5q3TgUygnUFf

Entry address:
0x5087F

Entry point:
E8, 8C, 8B, 01, 00, E9, 7F, FE, FF, FF, 6A, 10, 68, E0, 3E, 4A, 00, E8, EB, 5D, 00, 00, 33, F6, 89, 75, E4, 89, 75, E0, 89, 75, FC, 3B, 75, 10, 7D, 12, 8B, 4D, 08, FF, 55, 14, 8B, 45, 0C, 01, 45, 08, 46, 89, 75, E4, EB, E9, 33, C0, 40, 89, 45, E0, C7, 45, FC, FE, FF, FF, FF, E8, 0E, 00, 00, 00, E8, F7, 5D, 00, 00, C2, 14, 00, 8B, 75, E4, 8B, 45, E0, 85, C0, 75, 0F, FF, 75, 18, 56, FF, 75, 0C, FF, 75, 08, E8, 9A, 69, FF, FF, C3, E8, 32, 70, 00, 00, 69, 48, 14, FD, 43, 03, 00, 81, C1, C3, 9E, 26, 00, 89, 48...
 
[+]

Code size:
520 KB (532,480 bytes)

The file siinst-web.exe has been seen being distributed by the following 5 URLs.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to d3.16.e443.ip4.static.sl-reverse.com  (67.228.22.211:80)

Remove siinst-web.exe - Powered by Reason Core Security