winrar-dp.exe

Software

dobreprogramy sp. z o.o.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application winrar-dp.exe, “Software Setup ” by dobreprogramy sp. z o.o has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The installer is marketed through download protals and search ads as WinRAR archiver but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Generic internet   (signed by dobreprogramy sp. z o.o.)

Product:
Software

Description:
Software Setup

MD5:
88f97e7871cbef92c1238bfa85182f7d

SHA-1:
a5199928733f9f771b493598fff213b4d201b81e

SHA-256:
d534cb6781e2cea01cd46c04bba015b79fc56dba4cf8d0aaaaa04b108922414a

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/23/2024 4:19:03 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/InstallCore.BC.108
8.3.1.6

AVG
Adware InstallCore
2016.0.3042

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.15419

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.InstallCore.DSP
22232

Dr.Web
Trojan.InstallCore.283
9.0.1.0109

ESET NOD32
Win32/InstallCore.ZC potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/InstallCore
4/19/2015

K7 AntiVirus
Adware
13.204.16012

Malwarebytes
v2015.07.20.07

McAfee
Trojan.Artemis!88F97E7871CB
16.8.708.2

Reason Heuristics
PUP.Bundler.dobreprogramyspzoo
15.4.19.6

Total Defense
Win32/Tnega.VPDEPaC
37.1.62.1

Trend Micro House Call
Suspicious_GEN.F47V0405
7.2.109

VIPRE Antivirus
Threat.4150696
40432

File size:
720.9 KB (738,232 bytes)

Product version:
2.0.8

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\winrar-dp.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
2/25/2015 1:00:00 AM

Valid to:
2/26/2016 12:59:59 AM

Subject:
CN=dobreprogramy sp. z o.o., OU=IT, O=dobreprogramy sp. z o.o., L=Wroclaw, S=Dolnoslaskie, C=PL

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
04CCACE3AEB4566AFA610407D3C9D967

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:yDLGlCIuFubzhLpUuwweHLGwuDDG1XYJQLbqcDcV14iugvNAm5tWtr0qrWL8:yDLgCIuch1UuuG/m1XYaLqYiDV95I9r1

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file winrar-dp.exe has been seen being distributed by the following 14 URLs.

http://cdn.dobreprogramydownloads.com/c?x=zvRyfswh/BiZO9ueZL6CdeoYL i5JcjLkrVX6YdxXxs=&c= uzf8xHb7TZx8eD cUhF1kjGdyU4V7GHPJS LwW/L70cxkEX7XDnzPVbP4kSOL8aqlIrCpsih8n/J3Wcwq2lEQ==&fallback_url=http://storage.dobreprogramy.pl/.../winrar-x64-521pl.exe&downloadAs=WinRAR(12398)-dp.exe

http://cdn.dobreprogramydownloads.com/c?x=C5nLpIoYRxAdH2O0pDnjffV9UoguP62jrLNQ w6nhE0=&c=1mjmMfG/e8aPwTiUP0MQyd6qE0/8tpnUd9Or Ai2FfDdWQbvfOXttvnbclvZq4R QMzaj6KuWtL N0xz0flV8Q==&fallback_url=http://storage.dobreprogramy.pl/.../winrar-x64-521pl.exe&downloadAs=WinRAR(12398)-dp.exe

http://cdn.dobreprogramydownloads.com/c?x=hx/m6mS5l1Thi81GX/QJwiodFhzEiMXzTOyshGEwyEs=&c=XTjnJlPLqHdAmSOtDyUqSfDbdWhAvFmfVeqdrC aKEnI6nkqDdEvICUEL7NWPb/P4o1yRo/BmK1tzdStFO7C8A==&fallback_url=http://storage.dobreprogramy.pl/.../winrar-x64-521pl.exe&downloadAs=WinRAR(12398)-dp.exe

Remove winrar-dp.exe - Powered by Reason Core Security