telecharger_downloader_v4.0.3.6711_stub.exe

The application telecharger_downloader_v4.0.3.6711_stub.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from dnld.ironcust.com.
MD5:
435edf085d77d330749b2970fad6af33

SHA-1:
dc9047aac5119876e58a9c3eb05cdf41a5429a0f

SHA-256:
626f5285e3cb1d1c8f1ec4851c079d74ae85b89fd6787bc922f72f3172d1c83e

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/18/2024 5:43:51 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/ATRAPS.Gen2
7.11.30.172

ESET NOD32
Win32/Kryptik.PVK trojan
7.0.302.0

F-Prot
W32/InstallCore.G4.gen
v6.4.7.1.166

K7 AntiVirus
Trojan
13.183.13407

Malwarebytes
v2014.09.18.03

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

Rising Antivirus
PE:AdWare.Win32.InstallCore.i!1075350952
23.00.65.14916

Sophos
InstallCore ToDownload
4.98

Vba32 AntiVirus
3.12.26.3

File size:
634.9 KB (650,120 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\telecharger_downloader_v4.0.3.6711_stub.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:LEseRwfkP9HLZv8RXQbOfZe2QiF48TcqpelAZ3Wt1wxqYeawMYIkTcDKTanj:QNGkP5ZkRXQChBG1qcSZ3QwxZeawMhUM

Entry address:
0x1333B0

Entry point:
60, BE, 00, 00, 4A, 00, 8D, BE, 00, 10, F6, FF, C7, 87, 10, 47, 0E, 00, 25, 95, FC, 1D, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8514

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
592 KB (606,208 bytes)

The file telecharger_downloader_v4.0.3.6711_stub.exe has been seen being distributed by the following URL.

Remove telecharger_downloader_v4.0.3.6711_stub.exe - Powered by Reason Core Security