subtitles.exe

Subtitles 1.3

GT CONSULTORIA EM INFORMATICA LTDA

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application subtitles.exe, “Subtitles 1.3 Setup ” by GT CONSULTORIA EM INFORMATICAA has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from i1.stylezip.info and multiple other hosts.
Publisher:
Subtitles.com.br   (signed by GT CONSULTORIA EM INFORMATICA LTDA)

Product:
Subtitles 1.3

Description:
Subtitles 1.3 Setup

Version:
1.3

MD5:
303822ad709cc2e30e774f76c73ef1e7

SHA-1:
9eeb96223652b544ba1fb97d6f49db35f5778088

SHA-256:
0fbe6f53ce056b41fe3e1ad9aedeb103c3297e0cd2b2a82da069efba02af759f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/24/2024 3:19:21 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.GTCONSULTORIAEMINFORMATICAA.J
15.1.4.13

File size:
494 KB (505,840 bytes)

Product version:
1.3

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\subtitles.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
6/5/2013 1:00:00 AM

Valid to:
6/23/2014 1:00:00 PM

Subject:
CN=GT CONSULTORIA EM INFORMATICA LTDA, O=GT CONSULTORIA EM INFORMATICA LTDA, L=Juiz de Fora, S=Minas Gerais, C=BR

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06078E7C0FFB7F5B89A9F5369710BC1E

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:IQiGCzL8+iDNdRHRzty1GEU6lSrgRl7q3C8pJt+:IQin38Dd81G0M+l7u+

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file subtitles.exe has been seen being distributed by the following 2 URLs.

Remove subtitles.exe - Powered by Reason Core Security