virtualdub 1.10.1-test14 downloader.exe

Freemium GmbH

The application virtualdub 1.10.1-test14 downloader.exe by Freemium GmbH has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the Covus installer. The file has been seen being downloaded from downloader.chip.de.
Publisher:
Freemium GmbH  (signed and verified)

MD5:
74e112269c60bb6ad3ad88a9866b722c

SHA-1:
70e55793df694336c915dd57f7f9ad8489e9893f

SHA-256:
523d08b059b458547ff7adb1d6db6c62c65645aa4ec733d94c35b640d8c98d35

Scanner detections:
6 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/20/2024 6:24:44 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.3101

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Downware.10569
9.0.1.05190

Malwarebytes
PUP.Optional.Freemium.A
v2015.05.22.03

Reason Heuristics
PUP.Covus.Bundler
15.5.22.11

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.26.4

File size:
44.1 KB (45,176 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\virtualdub 1.10.1-test14 downloader.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
12/29/2014 4:41:38 PM

Valid to:
12/29/2015 4:41:38 PM

Subject:
CN=Freemium GmbH, O=Freemium GmbH, L=Berlin, C=DE

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00FEAC9D237F1C5C86

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:E4wO7XBz+5Qm3W0tYdrQZHV4EWuWEUOg4jjfS3XJp5gd0HVLlJSGiAC:nLXB65939tY6HBg4sXJp5gd0HZC

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file virtualdub 1.10.1-test14 downloader.exe has been seen being distributed by the following URL.

Remove virtualdub 1.10.1-test14 downloader.exe - Powered by Reason Core Security