tudo downloads mr. manager gold 1 (português).exe

IronInstall

The application tudo downloads mr. manager gold 1 (português).exe by IronInstall has been detected as adware by 4 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from tudodownloads.com.br.
Publisher:
IronInstall  (signed and verified)

MD5:
b3d6eb42648ed3dc683c3d3d4ae6cca8

SHA-1:
e7570a966823f54760572f1ac1fd24c6b7593ef6

SHA-256:
97f633b3efdeac8862c0e00c3072452987acd4d868ea5bf432f0773ced497764

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/15/2024 3:23:06 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Installer-I [PUP]
160216-0

AVG
Win32/Heim
2015.0.4533

ESET NOD32
Win32/InstallCore potentially unwanted application
8.0.319.0

Reason Heuristics
PUP.installCore.IronInst (M)
16.3.25.1

File size:
615.2 KB (629,976 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\tudo downloads mr. manager gold 1 (português).exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/20/2012 12:00:00 AM

Valid to:
11/20/2015 11:59:59 PM

Subject:
CN=IronInstall, O=IronInstall, STREET=63 Rothschild Blvd., L=Tel-Aviv, S=NA, PostalCode=65785, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2DC5BB8E9D823CD0C4F09AE859BBBEAC

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:4XAz7QMFk9oVhkNnO9TGzTwhvCUUfYH7eCbwhwJWYaVJmw2JxYmoIlVj5v:4cOoVhkRO9TkwQBgHdbpIYw2JO1Ij5v

Entry address:
0x132A10

Entry point:
60, BE, 00, 40, 4A, 00, 8D, BE, 00, D0, F5, FF, C7, 87, 10, 47, 0E, 00, 45, 96, FE, C0, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
572 KB (585,728 bytes)

The file tudo downloads mr. manager gold 1 (português).exe has been seen being distributed by the following URL.