winrar setup.exe

WeDownload, Ltd

The application winrar setup.exe by WeDownload has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the Midia Downloader installer. With this installer, users are expecting to download WinRAR archiver but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware. The file has been seen being downloaded from winrar.xtremedownload.com.
Publisher:
WeDownload, Ltd  (signed and verified)

MD5:
e1f0f00b7adc1d5e620527cc463b5271

SHA-1:
4bc0c4bc7fb106cda9bf3a0f4c4ec46dedfff3f8

SHA-256:
b2eec5207308dfc5aa215b065b6b075df5eef06c8434de211c026f19874c836e

Scanner detections:
20 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/17/2024 11:22:37 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Soft32Downloader
7.1.1

AhnLab V3 Security
Win-PUP/Soft32Downloader
2014.12.12

Avira AntiVirus
APPL/Downloader.Gen
7.11.194.194

avast!
Downloader-TOV [PUP]
141130-1

AVG
Wedownload
2015.0.3261

Clam AntiVirus
Win.Trojan.Agent-754117
0.98/21511

Comodo Security
UnclassifiedMalware
20343

Dr.Web
Adware.Downware.8933
9.0.1.05190

ESET NOD32
MSIL/Soft32Downloader.C potentially unwanted application
7.0.302.0

F-Secure
Riskware.Application.Generic.670361
5.13.68

G Data
Win32.Application.Soft32Downloader
14.12.24

K7 AntiVirus
Unwanted-Program
13.186.14309

Kaspersky
not-a-virus:Downloader.Win32.Agent
15.0.0.543

McAfee
Artemis!31199B186530
5600.6917

NANO AntiVirus
Trojan.Win32.Soft32Downloader.dgyrwy
0.28.6.63850

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
PUP.Installer.WeDownload.M
14.12.14.3

Vba32 AntiVirus
Signed-AdWare.WeDownload
3.12.26.3

VIPRE Antivirus
Threat.4150696
35418

Zillya! Antivirus
Downloader.Agent.Win32.203388
2.0.0.2004

File size:
779 KB (797,736 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Midia Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\winrar setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/6/2013 2:00:00 AM

Valid to:
2/11/2016 2:00:00 PM

Subject:
CN="WeDownload, Ltd", O="WeDownload, Ltd", L=Nicosia, C=CY

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0320C5B8F7CE6E92D3665598826A4480

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:gwMDD47E2/bDlvNXK6si6xhMiprWebxTAij1rlAUN4Cvt0RUli/F2mN:gtg7E2NvJAv/dqIxLjAUVl0RUlGYm

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file winrar setup.exe has been seen being distributed by the following URL.

Remove winrar setup.exe - Powered by Reason Core Security