webinstaller.exe

JDownloader2 (BETA)

AppWork GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application webinstaller.exe, “JDownloader2 (BETA) Setup for Windows” by AppWork GmbH has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from onedrive.live.com and multiple other hosts. While running, it connects to the Internet address installer.jdownloader.org on port 80 using the HTTP protocol.
Publisher:
AppWork GmbH  (signed and verified)

Product:
JDownloader2 (BETA)

Description:
JDownloader2 (BETA) Setup for Windows

Version:
2.0.0.2

MD5:
49b16f8996c6536ba29a9e595053e777

SHA-1:
5956ac8a2c31503b32cc7c82872de2ea95858336

SHA-256:
52ab42abaec91dd951c929af57d28898df93d4e654854f27259c23bfa3cba04d

Scanner detections:
3 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 3:45:17 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.11366268
0.98/21411

Reason Heuristics
PUP.Installer.AppWorkGmbH.M
14.7.28.0

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

File size:
74.6 KB (76,440 bytes)

Product version:
2.0.0.2

Copyright:
AppWork GmbH

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Nullsoft Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\webinstaller.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/31/2014 3:51:29 PM

Valid to:
4/1/2015 4:00:41 PM

Subject:
E=e-mail@appwork.org, CN=AppWork GmbH, O=AppWork GmbH, L=Fuerth, S=Bayern, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11218C489DBD3BC8AF35CDB519BA450DC59A

File PE Metadata
Compilation timestamp:
12/25/2013 6:01:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:pwDJZGrZopISbAoR8BXJXD9R9lFBtRThFTI7gxkNL82vzZsYTm7PBe:mDJ0rZo6StCBXJ57BtNAZ99sYa1e

Entry address:
0x3219

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 98, 37, 42, 00, E8, AD, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, A0, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 57, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 45, 2A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file webinstaller.exe has been seen being distributed by the following 4 URLs.

https://onedrive.live.com/download.aspx?cid=2CD0EB3FCC11E9BD&authKey=!AMslhGcPHhvr6rw&resid=2CD0EB3FCC11E9BD!19857&ithint=.exe

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to installer.jdownloader.org  (85.131.130.148:80)

Remove webinstaller.exe - Powered by Reason Core Security