webinstallerjd1.exe

JDownloader 0.9581

Appwork GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application webinstallerjd1.exe, “JDownloader 0.9581 Setup for Windows” by Appwork GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from installer.jdownloader.org and multiple other hosts. While running, it connects to the Internet address installer.jdownloader.org on port 80 using the HTTP protocol.
Publisher:
Appwork GmbH  (signed and verified)

Product:
JDownloader 0.9581

Description:
JDownloader 0.9581 Setup for Windows

Version:
2.0.0.5

MD5:
56e56298949b19856e51fe2638ae8bce

SHA-1:
ee667e1fcebbef7a495e79d4783884e3d109e644

SHA-256:
13393a85129dd0221d92b57da54ab091ead6f78591ecae2924714aeaa0104660

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/24/2024 11:29:47 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.AppworkGmbH.P
14.9.4.23

File size:
77.8 KB (79,696 bytes)

Product version:
2.0.0.5

Copyright:
AppWork GmbH

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Nullsoft Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\webinstallerjd1.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/14/2014 5:00:00 PM

Valid to:
8/15/2015 4:59:59 PM

Subject:
CN=Appwork GmbH, O=Appwork GmbH, L=Fürth, S=Bayern, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0091626FD168636EDD78A174E8B75DAC

File PE Metadata
Compilation timestamp:
5/11/2014 1:03:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:JkswQDYrZo5isPqo78fXJz19R9lFBtRThFTL4/fVYC7dgv4jI5IEjD:yDQkrZoosbIfXJ/7BtNTiY5IE3

Entry address:
0x3217

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 98, 37, 42, 00, E8, AD, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, A0, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 57, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 45, 2A...
 
[+]

Entropy:
6.8723

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file webinstallerjd1.exe has been seen being distributed by the following 50 URLs.

http://installer.jdownloader.org/wb130608948914295770one

http://installer.jdownloader.org/wb130604264809681743one

http://installer.jdownloader.org/wb130774878186973939one

http://installer.jdownloader.org/r_130725551134552336/2349/windows/32/.../jdownloader1

http://installer.jdownloader.org/wb130790339798837890one

http://installer.jdownloader.org/wb130774666180369971one

http://installer.jdownloader.org/wb130717204160287502one

http://installer.jdownloader.org/wb130613128211406250one

http://installer.jdownloader.org/wb130739296420312500one

http://installer.jdownloader.org/wb130811196948445474one

http://installer.jdownloader.org/wb130749884466194668one

http://installer.jdownloader.org/wb130760045175625000one

http://installer.jdownloader.org/wb130738289822055834one

http://installer.jdownloader.org/wb130704054282900479one

http://installer.jdownloader.org/wb130806066719925912one

http://installer.jdownloader.org/wb130632337929978480one

http://installer.jdownloader.org/wb130756586712760112one

http://installer.jdownloader.org/wb130563288623195360one

http://installer.jdownloader.org/wb130796041061037920one

http://installer.jdownloader.org/wb130750018511640999one

http://installer.jdownloader.org/wb130837121656935498one

http://installer.jdownloader.org/wb130772198654707998one

http://installer.jdownloader.org/wb130633319794746094one

http://installer.jdownloader.org/wb130556377288582207one

http://installer.jdownloader.org/wb130731329695108473one

blob:http://jdownloader.org:8080/401b77bb-f068-4d8d-a903-50e33ed36261

http://installer.jdownloader.org/wb130738176979911956one

http://installer.jdownloader.org/wb130724744037249121one

http://installer.jdownloader.org/wb130564849312527457one

http://installer.jdownloader.org/wb130780775320769011one

Latest 30 of 229 download URLs

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to installer.jdownloader.org  (85.131.130.148:80)

Remove webinstallerjd1.exe - Powered by Reason Core Security