sockshare.exe

Sergey Petrov

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application sockshare.exe by Sergey Petrov has been detected as adware by 20 anti-malware scanners. It uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme. The file has been seen being downloaded from toolkitfreefast.com.
Publisher:
Sergey Petrov  (signed and verified)

MD5:
5d691c9afa655d60c5d50de653892a61

SHA-1:
7744435860d31c6385ae901bf3a7db363dc39f50

SHA-256:
1932760b270e499f92393a1b2b6ac8e0f96c905e04c40acc682634baf32d004f

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Uses the InstalleRex from WebPick Internet Holdings to install bundled add-ons including toolbars and other web browser extensions.

Analysis date:
4/25/2024 8:39:07 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.DL.Agent
7.1.1

Avira AntiVirus
TR/Dldr.Agent.324784
7.11.145.12

avast!
Win32:InstalleRex-BI [PUP]
2014.9-140423

AVG
Generic_r
2015.0.3495

Comodo Security
Application.Win32.InstalleRex.AKF
18157

Dr.Web
Trojan.Siggen4.41297
9.0.1.0113

ESET NOD32
Win32/TrojanDownloader.Agent.AKF (variant)
8.9714

Fortinet FortiGate
W32/Agent.AKF!tr
4/23/2014

G Data
Win32.Application.EZDownloader
14.4.24

IKARUS anti.virus
Trojan-Dropper.Agent
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.176.11861

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.3970

Malwarebytes
PUP.Optional.Installrex
v2014.04.23.10

NANO AntiVirus
Trojan.Win32.Siggen4.cvpheq
0.28.0.59492

Panda Antivirus
Trj/Genetic.gen
14.04.23.10

Reason Heuristics
PUP.SergeyPetrov.J
14.4.23.20

Sophos
InstallRex
4.98

Total Defense
Win32/Tnega.KVDIJa
37.0.10895

Vba32 AntiVirus
TrojanDownloader.Agent
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28554

File size:
317.2 KB (324,800 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\sockshare.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/20/2013 8:00:00 PM

Valid to:
8/21/2014 7:59:59 PM

Subject:
CN=Sergey Petrov, O=Sergey Petrov, STREET=Gaydara 13, L=Kyev, S=Kyev, PostalCode=01033, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0AD084E865D27CD546D21DB6EDF89D48

File PE Metadata
Compilation timestamp:
3/3/2014 4:58:19 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:i40W7UXPpy1t5WfTAr9mbwJXOctWN5oZXuC+liAxprQZE:v0W7UXPp4t5O+9mbw/uC+YAxFQZE

Entry address:
0x1AC11

Entry point:
E8, 27, 80, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 9C, D5, 43, 00, 75, 02, F3, C3, E9, D2, 81, 00, 00, 55, 8B, EC, 8B, 45, 0C, 83, EC, 20, 56, 57, 6A, 08, 59, BE, FC, 27, 43, 00, 8D, 7D, E0, F3, A5, 8B, 4D, 08, 5F, 5E, 85, C0, 74, 0D, F6, 00, 10, 74, 08, 8B, 01, 8B, 40, FC, 8B, 40, 18, 89, 4D, F8, 89, 45, FC, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, F4, 10, 43, 00, C9, C2, 08, 00, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F...
 
[+]

Entropy:
5.9369

Code size:
188.5 KB (193,024 bytes)

The file sockshare.exe has been seen being distributed by the following URL.

Remove sockshare.exe - Powered by Reason Core Security