ultrasurf-1203-baixaki-32-bits.exe

The application ultrasurf-1203-baixaki-32-bits.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from dl.baixaki.com.br.
MD5:
39e995a406fe06c1c2850d4f3e92112e

SHA-1:
58d6d5cbb77f74e9f1e98c5aec5a7e719ab6fa39

SHA-256:
2a4d4a975ac3a09f8289c9a3b2dfd4cd66b7d0c79b2aaa117897d03b69f969a7

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/20/2024 1:49:23 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/InstallBai.A
7.11.99.136

Dr.Web
Adware.InstallCore.75
9.0.1.0353

ESET NOD32
Win32/InstallCore.AY (variant)
7.8746

F-Prot
W32/InstallCore.P.gen
v6.4.7.1.166

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.2691
3.12.22.3

VIPRE Antivirus
InstallCore
21038

File size:
1.1 MB (1,112,440 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ultrasurf-1203-baixaki-32-bits.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:BnnAN4/x6HgsUhm/BbMVN1eD4m8JeygtWpc4D:BnAW/Xp4/BYkvDt

Entry address:
0xCD560

Entry point:
55, 8B, EC, 83, C4, F0, B8, C4, 3D, 41, 00, E8, 59, F4, FF, FF, 3B, 00, 74, 23, 8B, D3, B8, E4, 25, 47, 00, E8, F5, FD, FF, FF, 84, C0, 75, 13, 68, 00, 80, 00, 00, 6A, 00, 8B, 03, 50, E8, 62, FD, FF, FF, 33, C0, 89, 03, 5D, 5F, 5E, 5B, C3, 90, 53, 56, 57, 55, 83, C4, EC, 89, 4C, 24, 04, 89, 14, 24, C7, 44, 24, 08, FF, FF, FF, FF, 33, D2, 89, 54, 24, 0C, 8B, E8, 8B, 04, 24, 03, C5, 89, 44, 24, 10, 8B, 1D, E4, 25, 47, 00, EB, 51, 8B, 3B, 8B, 73, 08, 3B, EE, 77, 46, 8B, C6, 03, 43, 0C, 3B, 44, 24, 10, 77, 3B...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
837.5 KB (857,600 bytes)

The file ultrasurf-1203-baixaki-32-bits.exe has been seen being distributed by the following URL.

Remove ultrasurf-1203-baixaki-32-bits.exe - Powered by Reason Core Security